POSTAuthentication
Get Authentication
/oauth/accesstoken
Exchange a client ID and client secret for the access token used by protected endpoints.
Source: API Documentation.pdf, page 1Client credentials flow
Exchange your client ID and client secret for an access token. Use the returned token as the Authorization header value on every protected Hotel, Flight, and Refund request. Never place production credentials in documentation or client-side code.
Source notes
Source ambiguityThe source names the expiry field `expired_in`; it is preserved exactly rather than changed to the more common `expires_in`.
Parameters
| Name | Type | Example | Description |
|---|---|---|---|
client_idRequired | String | <client id> | Client's ID |
client_secretRequired | String | <client secret> | Client's password |
access_token | String | <access token> | JSON Web Token |
expired_in | Timestamp | 3600000 | Expired time for the token |
token_type | String | Bearer | Standard OAuth 2.0 token type |