> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.crisscross.money/api-reference/authentication/request-access-token/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.crisscross.money/_mcp/server. # Request an Access Token POST https://api.crisscross.money/v1/auth/oauth2/token Content-Type: application/json Retrieve an access token to authenticate your requests to all CrissCross APIs (Collect, Exchange, and Payouts). The access token will be valid for a limited duration indicated by the `expires_in` field in the response. Store the token until it expires, then request a new one. Reference: https://docs.crisscross.money/api-reference/authentication/request-access-token ## Request ### Body (application/json) This endpoint expects an OAuthTokenRequest. - `client_id` (string, required) — The client identifier. - `client_secret` (string, required) — The client secret for the merchant. ## Response ### 200 OK - A successful access token response. - `access_token` (string, required) — The access token to be used for authentication. - `token_type` (string, required) — The type of the token issued. - `expires_in` (double, required) — The duration in seconds for which the token is valid. ## Errors ### 400 Bad Request Error Bad Request - Invalid request parameters. - `error` (string, optional) — Description of the error. ### 401 Unauthorized Error Unauthorized - Invalid client credentials. - `error` (string, optional) — Description of the error. ### 503 Service Unavailable Error Service Unavailable - temporary outage of the authentication service; retry with backoff. - `error` (string, optional) — Description of the error. ## Examples **Request** ```json { "client_id": "1b2a3d4c-5e6f-7a8b-9c0d-1e2f3a4b5c6d", "client_secret": "your-client-secret" } ``` **Response** ```json { "access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...", "token_type": "Bearer", "expires_in": 86400 } ``` **SDK Code** ```python requestAccessToken_example import requests url = "https://api.crisscross.money/v1/auth/oauth2/token" payload = { "client_id": "1b2a3d4c-5e6f-7a8b-9c0d-1e2f3a4b5c6d", "client_secret": "your-client-secret" } headers = {"Content-Type": "application/json"} response = requests.post(url, json=payload, headers=headers) print(response.json()) ``` ```javascript requestAccessToken_example const url = 'https://api.crisscross.money/v1/auth/oauth2/token'; const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"client_id":"1b2a3d4c-5e6f-7a8b-9c0d-1e2f3a4b5c6d","client_secret":"your-client-secret"}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go requestAccessToken_example package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://api.crisscross.money/v1/auth/oauth2/token" payload := strings.NewReader("{\n \"client_id\": \"1b2a3d4c-5e6f-7a8b-9c0d-1e2f3a4b5c6d\",\n \"client_secret\": \"your-client-secret\"\n}") req, _ := http.NewRequest("POST", url, payload) req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby requestAccessToken_example require 'uri' require 'net/http' url = URI("https://api.crisscross.money/v1/auth/oauth2/token") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Post.new(url) request["Content-Type"] = 'application/json' request.body = "{\n \"client_id\": \"1b2a3d4c-5e6f-7a8b-9c0d-1e2f3a4b5c6d\",\n \"client_secret\": \"your-client-secret\"\n}" response = http.request(request) puts response.read_body ``` ```java requestAccessToken_example import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.post("https://api.crisscross.money/v1/auth/oauth2/token") .header("Content-Type", "application/json") .body("{\n \"client_id\": \"1b2a3d4c-5e6f-7a8b-9c0d-1e2f3a4b5c6d\",\n \"client_secret\": \"your-client-secret\"\n}") .asString(); ``` ```php requestAccessToken_example request('POST', 'https://api.crisscross.money/v1/auth/oauth2/token', [ 'body' => '{ "client_id": "1b2a3d4c-5e6f-7a8b-9c0d-1e2f3a4b5c6d", "client_secret": "your-client-secret" }', 'headers' => [ 'Content-Type' => 'application/json', ], ]); echo $response->getBody(); ``` ```csharp requestAccessToken_example using RestSharp; var client = new RestClient("https://api.crisscross.money/v1/auth/oauth2/token"); var request = new RestRequest(Method.POST); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{\n \"client_id\": \"1b2a3d4c-5e6f-7a8b-9c0d-1e2f3a4b5c6d\",\n \"client_secret\": \"your-client-secret\"\n}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift requestAccessToken_example import Foundation let headers = ["Content-Type": "application/json"] let parameters = [ "client_id": "1b2a3d4c-5e6f-7a8b-9c0d-1e2f3a4b5c6d", "client_secret": "your-client-secret" ] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://api.crisscross.money/v1/auth/oauth2/token")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "POST" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```