Authentication
Issue a Token
Generate an access token using client credentials
POST
/
v1
/
oauth
/
token
Issue a Token
curl --request POST \
--url https://sandbox.api.fin.com/v1/oauth/token \
--header 'Content-Type: application/json' \
--data '
{
"client_id": "<string>",
"client_secret": "<string>"
}
'const url = 'https://sandbox.api.fin.com/v1/oauth/token';
const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({client_id: '<string>', client_secret: '<string>'})
};
fetch(url, options)
.then(res => res.json())
.then(json => console.log(json))
.catch(err => console.error(err));HttpResponse<String> response = Unirest.post("https://sandbox.api.fin.com/v1/oauth/token")
.header("Content-Type", "application/json")
.body("{\n \"client_id\": \"<string>\",\n \"client_secret\": \"<string>\"\n}")
.asString();import requests
url = "https://sandbox.api.fin.com/v1/oauth/token"
payload = {
"client_id": "<string>",
"client_secret": "<string>"
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://sandbox.api.fin.com/v1/oauth/token"
payload := strings.NewReader("{\n \"client_id\": \"<string>\",\n \"client_secret\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}{
"data": {
"access_token": "LIZqxTM9NgEgvCSCgwCKCSl4dTVCPAYE59fTOZs6gwvup4TQuD",
"access_token_ttl": "2026-09-24 09:26:24+00",
"refresh_token": "FEWWXAMXPFSc8uAgDlRXk6zlCxBSKGM6GlAYxRpYwdDRMkiXIm",
"refresh_token_ttl": "2026-09-30 09:26:24+00",
"current_time": "2026-09-23 09:26:24+00"
}
}{
"message": "Authentication failed"
}{
"message": "<string>",
"errors": [
{}
]
}Grab your
client_id and client_secret from the
API Keys section
of the Orchestration Dashboard
- The TTLs returned from this API are actually the time that the token will expire; i.e. not validity in number of seconds since creation.
- The timestamps, i.e. TTLs returned from this endpoint are NOT in ISO 8601 format. Rather it is in the format
YYYY-MM-DD HH:MM:SS+00.
⌘I
Issue a Token
curl --request POST \
--url https://sandbox.api.fin.com/v1/oauth/token \
--header 'Content-Type: application/json' \
--data '
{
"client_id": "<string>",
"client_secret": "<string>"
}
'const url = 'https://sandbox.api.fin.com/v1/oauth/token';
const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({client_id: '<string>', client_secret: '<string>'})
};
fetch(url, options)
.then(res => res.json())
.then(json => console.log(json))
.catch(err => console.error(err));HttpResponse<String> response = Unirest.post("https://sandbox.api.fin.com/v1/oauth/token")
.header("Content-Type", "application/json")
.body("{\n \"client_id\": \"<string>\",\n \"client_secret\": \"<string>\"\n}")
.asString();import requests
url = "https://sandbox.api.fin.com/v1/oauth/token"
payload = {
"client_id": "<string>",
"client_secret": "<string>"
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://sandbox.api.fin.com/v1/oauth/token"
payload := strings.NewReader("{\n \"client_id\": \"<string>\",\n \"client_secret\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}{
"data": {
"access_token": "LIZqxTM9NgEgvCSCgwCKCSl4dTVCPAYE59fTOZs6gwvup4TQuD",
"access_token_ttl": "2026-09-24 09:26:24+00",
"refresh_token": "FEWWXAMXPFSc8uAgDlRXk6zlCxBSKGM6GlAYxRpYwdDRMkiXIm",
"refresh_token_ttl": "2026-09-30 09:26:24+00",
"current_time": "2026-09-23 09:26:24+00"
}
}{
"message": "Authentication failed"
}{
"message": "<string>",
"errors": [
{}
]
}