Machine translation, not yet reviewed.

Authentication and authorization

This guide shows how to authenticate requests to the Tax360 APIs and how to manage the lifecycle of the JWT token.

Objective

This guide shows how to authenticate requests to the Tax360 APIs and how to manage the lifecycle of the JWT token.

Prerequisites

  • Access to the IAM portal with a Super User account.
  • An API key already created in the IAM portal.

1. Obtain a JWT token

Make a request to the token generation endpoint:

# PRD
POST https://<API_HOST>/api/integration/auth/token

# UAT / QA
POST https://<API_HOST>/api/integration/auth/token

See the interactive documentation for the endpoint at: Get Token — API Reference

Get access tokenPOST/api/integration/auth/tokenSign in to see the host and reference

The response will include, among other fields, the token and the expiration time:

{
  "token": "eyXXXXXXXXXX",
  "expires_in": 3600
}
FieldTypeDescription
tokenstringJWT token for authentication.
expires_inintegerToken lifetime, in seconds, from the moment it is generated.

To obtain a token using an API key, use:

  • grant_type: client_credentials
  • client_id: the client id obtained when the API key was created
  • client_secret: the client secret obtained when the API key was created

2. Send the token in requests

Include the token in the HTTP Authorization header with the Bearer scheme:

Authorization: Bearer eyXXXXXXXXXX

All requests to protected endpoints must contain this header.

3. Manage token expiration

Every token has a validity period defined when the API key is created. To avoid failures due to an expired token:

  1. When you obtain the token, calculate the expiration date based on the value of expires_in.
  2. Monitor the remaining time before each request.
  3. When approximately 30 seconds remain before expiration, generate a new token before proceeding.

Tip: store the calculated expiration date (e.g., Instant.now().plusSeconds(expiresIn)) and compare it before each call. This avoids unnecessary requests to the token endpoint.

HTTP codeMeaningRecommended action
401Invalid or expired token.Generate a new token and retry the request.
403Permission denied.Check whether the API key has the permissions required for the requested operation.

On this page