Authentication
Authentication
All requests to the CrissCross APIs (Collect, Exchange, and Payouts) require an access token. CrissCross uses OAuth 2.0 style access tokens for authenticating API requests. Authentication is machine-to-machine: request a token with your client_id and client_secret, then include it as a Bearer token in the Authorization header on every subsequent request.
Request an access token
POST https://api.crisscross.money/v1/auth/oauth2/token
The body must be JSON — form-encoded bodies are rejected with 400. No grant_type, scope, or audience is needed; client credentials is implied.
Response
Store the token until it expires. expires_in is the token’s lifetime in seconds (currently 86400, or 24 hours). There is no refresh token; request a new token when the current one expires.
Use the token
Handling authentication failures
Errors from the token endpoint are a single-field envelope, {"error": "<description>"}:
On every other API call, a missing, invalid, or expired access token returns 401 with a different envelope: {"message": "Unauthorized"}. If you see that shape, request a new token and retry.
Best practices
- Secure storage: keep your
client_secretand access tokens in a secrets manager or environment variables, never in source code. - Rotate on compromise: if your
client_secretis exposed, rotate it immediately.