Перейти до вмісту

Автентифікація

Exchange your key id + secret for a short-lived bearer token. Send it as `Authorization: Bearer …` together with `X-API-Key: {client_id}` on every call.

post/v1/oauth/token

  • Потрібна автентифікація

Тіло запиту

  • grant_typestring

    Must be `client_credentials`.

  • client_idstring

    Your key id (`dt_live_…` / `dt_sbx_…`).

  • client_secretstring

    Your client secret.

  • scopestring

    Optional space-separated subset of your granted scopes.

Приклад
{
  "grant_type": "string",
  "client_id": "string",
  "client_secret": "string",
  "scope": "string"
}

Відповіді

200OKTokenResponse

  • accessTokenstring
  • tokenTypestring
  • expiresIninteger (int32)
  • scopestring

    Space-separated scopes the token carries.

  • environmentstring

    Which environment this token is valid on.

  • 400Bad RequestОпис проблеми за RFC 7807
  • 401UnauthorizedОпис проблеми за RFC 7807

Приклади коду

Повноцінні програми, що підписують запит саме так, як його перевіряє шлюз. Замініть YOUR_KEY_ID і YOUR_SECRET.

curl -X POST "https://api.dubaitrip.com/v1/oauth/token" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "grant_type=client_credentials" \
  -d "client_id=YOUR_KEY_ID" \
  -d "client_secret=YOUR_SECRET"