> ## Documentation Index
> Fetch the complete documentation index at: https://docs-api.kravata.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Get Access Token

> By consuming this endpoint, you can request the refresh and access token. Provide your username and password in the request body.

#### Request Body

| Field | **Type** | Required | Description |
| --- | --- | --- | --- |
| username | string | Yes | Your username for authentication. |
| password | string | Yes | Your password for authentication. |

#### Response

| Field | Description |
| --- | --- |
| access | The access token, valid for 5 minutes, is used to authenticate requests to other endpoints. |
| refresh | The refresh token, valid for 24 hours, allows you to renew your access token when it expires. |



## OpenAPI

````yaml /business/openapi.json post /api/token
openapi: 3.1.0
info:
  title: Kravata Business API
  version: '1.0'
  description: >-
    Kravata Business API: on-ramp and off-ramp orders between fiat and
    stablecoins for your own accounts and wallets.
servers:
  - url: https://testapi.kravata.co
    description: Test
  - url: https://apiv2.kravata.co
    description: Production
security:
  - bearerAuth: []
tags:
  - name: Authentication
  - name: Accounts
  - name: Wallets
  - name: Ramp Orders
  - name: Webhooks
paths:
  /api/token:
    post:
      tags:
        - Authentication
      summary: Get Access Token
      description: >-
        By consuming this endpoint, you can request the refresh and access
        token. Provide your username and password in the request body.


        #### Request Body


        | Field | **Type** | Required | Description |

        | --- | --- | --- | --- |

        | username | string | Yes | Your username for authentication. |

        | password | string | Yes | Your password for authentication. |


        #### Response


        | Field | Description |

        | --- | --- |

        | access | The access token, valid for 5 minutes, is used to
        authenticate requests to other endpoints. |

        | refresh | The refresh token, valid for 24 hours, allows you to renew
        your access token when it expires. |
      operationId: get-access-token
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                username:
                  type: string
                password:
                  type: string
            example:
              username: '{{username}}'
              password: '{{password}}'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  refresh:
                    type: string
                  access:
                    type: string
              examples:
                api-token:
                  summary: api/token
                  value:
                    refresh: <jwt>
                    access: <jwt>
      security: []
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: Access token from POST /api/token (valid 5 minutes).

````