Skip to main content
Kravata assigns a username and password to accepted customers after the onboarding and compliance review. You exchange them for two JWT tokens:

Get your tokens

Refresh the access token

When the access token expires, request a new one with the refresh token:
When the refresh token also expires, request a new pair with POST /api/token.

Authenticate your requests

Most endpoints also require your clientId, in the path (/api/accounts/{clientId}) or as a query parameter (/api/ramps?clientId=...). Get it from Get Client Info.
Call the API only from your backend. Never expose your password or tokens in a browser or mobile app.