Skip to main content
The chmod API uses the OAuth 2.0 client credentials grant. Your backend exchanges a client id and secret for a short-lived bearer token, then sends that token on every call.
These credentials belong on your server only. Never ship them in a mobile app, a browser bundle or a public repository. Your app receives an sdk_token scoped to a single transaction instead — that is the whole point of the split.

Request a token

Parameters

string
required
Always client_credentials.
string
required
Your account’s OAuth client id.
string
required
Your account’s OAuth client secret.
string
required
Always account-integration-api/account-api-access.

Response

string
The bearer token to send on API calls.
integer
Lifetime in seconds.
string
Always Bearer.

Use the token

Every request to the chmod API carries the token in the Authorization header, with the Bearer scheme:
The same header goes on every endpoint — creating customers, creating transactions and reading results. There is nothing else to sign and no per-request nonce. A token is valid for one hour. Reuse it across requests until it expires; when the API answers 401, request a new one and retry. Tokens are not single-use, and requesting a new one does not invalidate the previous one.
The token identifies your account, not a user. Requests made with it act on your account’s customers and transactions, so keep it on the server and never forward it to a device.