Machine translation, not yet reviewed.
Authentication and authorization
This guide shows how to authenticate requests to the Tax360 APIs and how to manage the lifecycle of the JWT token.
Objective
This guide shows how to authenticate requests to the Tax360 APIs and how to manage the lifecycle of the JWT token.
Prerequisites
- Access to the IAM portal with a Super User account.
- An API key already created in the IAM portal.
1. Obtain a JWT token
Make a request to the token generation endpoint:
# PRD
POST https://<API_HOST>/api/integration/auth/token
# UAT / QA
POST https://<API_HOST>/api/integration/auth/tokenSee the interactive documentation for the endpoint at: Get Token — API Reference
Get access tokenPOST/api/integration/auth/tokenSign in to see the host and reference
The response will include, among other fields, the token and the expiration time:
{
"token": "eyXXXXXXXXXX",
"expires_in": 3600
}
| Field | Type | Description |
|---|---|---|
token | string | JWT token for authentication. |
expires_in | integer | Token lifetime, in seconds, from the moment it is generated. |
To obtain a token using an API key, use:
- grant_type: client_credentials
- client_id: the client id obtained when the API key was created
- client_secret: the client secret obtained when the API key was created
2. Send the token in requests
Include the token in the HTTP Authorization header with the Bearer scheme:
Authorization: Bearer eyXXXXXXXXXX
All requests to protected endpoints must contain this header.
3. Manage token expiration
Every token has a validity period defined when the API key is created. To avoid failures due to an expired token:
- When you obtain the token, calculate the expiration date based on the value of
expires_in. - Monitor the remaining time before each request.
- When approximately 30 seconds remain before expiration, generate a new token before proceeding.
Tip: store the calculated expiration date (e.g.,
Instant.now().plusSeconds(expiresIn)) and compare it before each call. This avoids unnecessary requests to the token endpoint.
Authentication-related error responses
| HTTP code | Meaning | Recommended action |
|---|---|---|
401 | Invalid or expired token. | Generate a new token and retry the request. |
403 | Permission denied. | Check whether the API key has the permissions required for the requested operation. |