Skip to main content

Login

The Transaction API uses a robust authentication system based on JWT (JSON Web Tokens) to guarantee the security and isolation of transactions.

Getting Credentials​

Prerequisites​

  • You must have an account registered on the platform.

Available Environments​

https://api.gateway.com.br/core

Authentication Process​

Endpoint​

  • Method: POST
  • Endpoint: /auth/token

Required Credentials​

CredentialDescriptionRequired
client_idUnique identifierYes
client_secretAuthentication secret keyYes

For your first access, get the credentials through the app; if you already have access, get the credentials through the api

Request Example​

curl --request POST \
--url https://api.gateway.com.br/core/auth/token \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode 'client_id=your-client-id' \
--data-urlencode 'client_secret=your-client-secret' \
--data-urlencode 'grant_type=client_credentials'

Success Response​

FieldTypeDescription
access_tokenstringJWT token for authentication
expires_innumberUnix timestamp of when the token expires
refresh_expires_innumberExpiration time of the refresh token
token_typestringToken type (always "Bearer")
not-before-policynumberNot-before policy
scopestringAccess scopes of the token
expires_in_secnumberToken lifetime in seconds

Note: the scope field returns the scopes separated by commas.

Response Example​

{
"access_token": "eyJhbGci...",
"expires_in": 1759845450,
"refresh_expires_in": 0,
"token_type": "Bearer",
"not-before-policy": 0,
"scope": "email,profile",
"expires_in_sec": 3600
}

Using the Token on Requests​

On every request to the API, include the JWT token in the Authorization header.

curl --request POST \
--url https://api.gateway.com.br/core/transaction \
--header 'Authorization: Bearer your-jwt-token' \
--header 'Content-Type: application/json' \
--data '{
// your payload here
}'

Error Handling​

CodeDescription
401Invalid credentials
400Malformed credentials
502Bad Gateway (error reaching the authentication provider)

Note: error codes and messages may vary according to the response of the authentication provider.

Security Best Practices​

  1. Token Management

    • Store tokens securely
    • Renew them before they expire
    • Never expose client_secret
    • Revalidate and rotate the secret key periodically, and whenever the team or the structure of the organization changes
  2. Security Headers

    • Use HTTPS in production
    • Implement rate limiting
    • Validate authentication on every request
  3. Monitoring

    • Log access attempts
    • Watch for suspicious patterns
    • Set up alerts