Authentication

The SignumEra API uses OAuth 2.0 access tokens issued by Laravel Passport.

Server-to-server integrations use the OAuth 2.0 Client Credentials Grant.

Your Client ID and Client Secret identify your application. Keep the Client Secret on your server and never expose it in browser JavaScript, mobile application source code, public repositories or URLs.

Obtain an Access Token

POST /oauth/token
curl -X POST \
  "https://api.signumera.com/oauth/token" \
  -H "Accept: application/json" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "grant_type=client_credentials" \
  -d "client_id=YOUR_CLIENT_ID" \
  -d "client_secret=YOUR_CLIENT_SECRET"

Example Response

{
    "token_type": "Bearer",
    "expires_in": 3600,
    "access_token": "YOUR_ACCESS_TOKEN"
}

Use the Access Token

Authorization: Bearer YOUR_ACCESS_TOKEN

Authentication Errors

Status Description
401 Access token is missing, invalid or expired.
403 The authenticated client is not permitted to perform the requested operation.