Authentification
Exchange your key id + secret for a short-lived bearer token. Send it as `Authorization: Bearer …` together with `X-API-Key: {client_id}` on every call.
post/v1/oauth/token
- Authentification requise
Corps de la requête
- grant_typestring
Must be `client_credentials`.
- client_idstring
Your key id (`dt_live_…` / `dt_sbx_…`).
- client_secretstring
Your client secret.
- scopestring
Optional space-separated subset of your granted scopes.
Exemple
{
"grant_type": "string",
"client_id": "string",
"client_secret": "string",
"scope": "string"
}Réponses
200OKTokenResponse
- accessTokenstring
- tokenTypestring
- expiresIninteger (int32)
- scopestring
Space-separated scopes the token carries.
- environmentstring
Which environment this token is valid on.
- 400Bad RequestDétails du problème RFC 7807
- 401UnauthorizedDétails du problème RFC 7807
Exemples de code
Des programmes complets qui signent la requête exactement comme la passerelle la vérifie. Remplacez YOUR_KEY_ID et YOUR_SECRET.
curl -X POST "https://api.dubaitrip.com/v1/oauth/token" \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "grant_type=client_credentials" \
-d "client_id=YOUR_KEY_ID" \
-d "client_secret=YOUR_SECRET"