Login
The Transaction API uses a robust authentication system based on JWT (JSON Web Tokens) to guarantee the security and isolation of transactions.
Getting Credentials
Prerequisites
- You must have an account registered on the platform.
Available Environments
- Production
https://api.gateway.com.br/core
Authentication Process
Endpoint
- Method:
POST - Endpoint:
/auth/token
Required Credentials
| Credential | Description | Required |
|---|---|---|
client_id | Unique identifier | Yes |
client_secret | Authentication secret key | Yes |
For your first access, get the credentials through the app; if you already have access, get the credentials through the api
Request Example
- cURL
- JavaScript
curl --request POST \
--url https://api.gateway.com.br/core/auth/token \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode 'client_id=your-client-id' \
--data-urlencode 'client_secret=your-client-secret' \
--data-urlencode 'grant_type=client_credentials'
const response = await fetch('https://api.gateway.com.br/core/auth/token', {
method: 'POST',
headers: {
'Content-Type': 'application/x-www-form-urlencoded',
},
body: new URLSearchParams({
client_id: 'your-client-id',
client_secret: 'your-client-secret',
grant_type: 'client_credentials'
})
});
const { access_token, expires_in } = await response.json();
Success Response
| Field | Type | Description |
|---|---|---|
access_token | string | JWT token for authentication |
expires_in | number | Unix timestamp of when the token expires |
refresh_expires_in | number | Expiration time of the refresh token |
token_type | string | Token type (always "Bearer") |
not-before-policy | number | Not-before policy |
scope | string | Access scopes of the token |
expires_in_sec | number | Token lifetime in seconds |
Note: the
scopefield returns the scopes separated by commas.
Response Example
{
"access_token": "eyJhbGci...",
"expires_in": 1759845450,
"refresh_expires_in": 0,
"token_type": "Bearer",
"not-before-policy": 0,
"scope": "email,profile",
"expires_in_sec": 3600
}
Using the Token on Requests
On every request to the API, include the JWT token in the Authorization header.
- cURL
- JavaScript
- Python
curl --request POST \
--url https://api.gateway.com.br/core/transaction \
--header 'Authorization: Bearer your-jwt-token' \
--header 'Content-Type: application/json' \
--data '{
// your payload here
}'
const response = await fetch('https://api.gateway.com.br/core/transaction', {
method: 'POST',
headers: {
'Authorization': `Bearer ${token}`,
'Content-Type': 'application/json'
},
body: JSON.stringify({
// your payload here
})
});
response = requests.post(
"https://api.gateway.com.br/core/transaction",
headers={
'Authorization': f'Bearer {token}',
'Content-Type': 'application/json'
},
json={
# your payload here
}
)
Error Handling
| Code | Description |
|---|---|
| 401 | Invalid credentials |
| 400 | Malformed credentials |
| 502 | Bad Gateway (error reaching the authentication provider) |
Note: error codes and messages may vary according to the response of the authentication provider.
Security Best Practices
-
Token Management
- Store tokens securely
- Renew them before they expire
- Never expose client_secret
- Revalidate and rotate the secret key periodically, and whenever the team or the structure of the organization changes
-
Security Headers
- Use HTTPS in production
- Implement rate limiting
- Validate authentication on every request
-
Monitoring
- Log access attempts
- Watch for suspicious patterns
- Set up alerts