Authentication - Generate Refresh Token

The Refresh Token API is used to extend the lifetime of the Access Token.

Used in Gateway Integration

Overview

The Refresh Token API is used to extend the lifetime of the Access Token so that it can be continuously be used in future API requests.

API Description

Headers

HeaderDescription/Value
Content-Typeapplication/vnd.carry1st.payments.partnerauthentication+json
Acceptapplication/vnd.carry1st.payments.partnerauthentication+json

URL Format

POST /api/pay1st/auth/refresh

POST Request Fields

The fields in the table below should be submitted as a JSON object.

ParameterFormatMandatoryDescription
roleStringYThis should be set to API_USER
refreshTokenStringYThis is a preceding refresh token that is obtained from either

Response

The API will respond with a JSON object containing the authentication and refresh tokens

Example Response

{
    "role": "API_USER",
    "accessToken": "MTRudXRiRDYvUGY1T2FiVDcrYi9aYzFVdkJBRG1YWHgxcnY1MkVwTm1taWJWdDNOSGRocXpLOHB5UlR3d083RmZ4Q0pLSGlLdE1Kc2JEOWszWUE4a3crc2NiR210Q1VUNGt0THlCWW5TM1psNGVwWmJOQ1cvTThxRWN2dVNDMXhrWmhpVTdWZkZGb1l5cCtybGtlUVBWejVaQVV6Tmo2a2RZYWRncnNkQWtnSXZMM3k2OUZLZTcrUWRwL1djUjlsYkNBcElnVzFMdjhSK2ROem1aUkVsLzBQeVJWaW55b29IVWhMMm9FT0kxQnFFa2VFNkJUR3V6VHY2V0s2UlNrQUFZVS9pUEU0dUkvaUhiQXgwY1JrelcvdzNDU0ZJTXRQSTR0L1hucnE4alNoUlU3bU53NWg0MUp4UnlQeDFIZXFEOGdPMkdhbUpOMXFaWXR0OTFIV0pWanJ2S3I0WmNGMkorWmI2ZTlUYWJORDVaeUl2VURiT1NNMUJQZi95WFkweENnQmdsbWdySjVWTk02a3FleURoTnIzSWduZXBaOHZBVSs3aHU5dzlYMVNPclVIRy95U3pWQWtVL2VjVTgzRUQvcU9qTVN3K0RMd0FNYUZsVS85am1VU21JZDRwMEVGZkxoTm1lRzJ5My8xeDdyRjBST01WY1RETWh4emx0UVM=",
    "refreshToken": "MTRudXRiRDYvUGY1T2FiVDcrYi9aYzFVdkJBRG1YWHgxcnY1MkVwTm1taWJWdDNOSGRocXpLOHB5UlR3d083RmZ4Q0pLSGlLdE1Kc2JEOWszWUE4azIyQ3JnbUpPdnRmaEcwTlE0K3RZUjhlME81TWd2TkJxYnVGOVNVYWVvMTFPUzVFT1BqVGZlUGZYL1pxZU56Q3d1Zmx4K0xZem1XSEVjV292a1FaSEhBSXZMM3k2OUZLZTcrUWRwL1djUjlsYkNBcElnVzFMdjhSK2ROem1aUkVsLzBQeVJWaW55b29IVWhMMm9FT0kxQVU4VnNXRHNTQy9qaUtPblN1aU05Q2xyWmV0aWg4alhGYkxKVzQxR2xWSlJkNzU0M0hsaHFXa25ISjBtV0xZbVJ1elpvWU5TVzFPenc1eVBhS0tSbFBOV040RVNZV3Y1VlN0MmdjbUpQYUluYWZuZVIvaDRIUGxuWlE1MTZXYy91MENjQi9wdE5aQ2Zrb21LbVVMVnhJQ3haa2p3V2NYZWl0dG5xbEVTYk1KL05ZVC94a2doaWN4OEIrRjdzVmVMUVN4anF4UE5PRTBZSGM0Z0NxRVFWU0VUVW5NaE9hZndZK09TREZtSlFYdTFXeC9kU29wUGREQ1VudUt5MGRvbzVwTEVudFRsRFRIMzlkZld3Yk5xaEw="
}

Each payment method in the response contains the following fields:

FieldFormatDescription
roleStringThis will be the same role as specified in the request.
accessTokenStringAn encrypted token to use for subsequent API requests.
refreshTokenStringThe refresh token is used when there is a need to increase the expiry time of an accessToken.

HTTP Response Codes

The payment method API may return the following HTTP Response Codes:

HTTP Status CodeNameDescription
200SuccessThis indicates that the request has been successful.
400Bad RequestThis indicates that that an error occurred in the request. See Handling Error Codes
401Unauthorized

The incorrect role value was used

The incorrect API Key and API Secret combination was used (see Configuring API Credentials )

403ForbiddenThe incorrect API Key and API Secret do not have the appropriate permissions to make the request
429Too Many RequestsThe Partner is sending too many requests to this endpoint and will be rate limited

Error Handling

See Handling Error Codes for more details on handling error responses.