API Reference
POSTAuthentication

Get Authentication

/oauth/accesstoken

Exchange a client ID and client secret for the access token used by protected endpoints.

Source: API Documentation.pdf, page 1

Client credentials flow

Exchange your client ID and client secret for an access token. Use the returned token as the Authorization header value on every protected Hotel, Flight, and Refund request. Never place production credentials in documentation or client-side code.

Source notes

Source ambiguityThe source names the expiry field `expired_in`; it is preserved exactly rather than changed to the more common `expires_in`.

Parameters

NameTypeExampleDescription
client_idRequiredString<client id>Client's ID
client_secretRequiredString<client secret>Client's password
access_tokenString<access token>JSON Web Token
expired_inTimestamp3600000Expired time for the token
token_typeStringBearerStandard OAuth 2.0 token type