> ## Documentation Index
> Fetch the complete documentation index at: https://docs-api.kravata.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Obtain and refresh access tokens for the Kravata Business API.

Kravata assigns a `username` and `password` to accepted customers after the onboarding and compliance review. You exchange them for two JWT tokens:

| Token | Validity | Use |
| - | - | - |
| `access` | 5 minutes | Send it as `Authorization: Bearer <access>` in every request. |
| `refresh` | 24 hours | Exchange it for a new `access` token without sending your password again. |

## Get your tokens

```bash theme={null}
curl -X POST https://testapi.kravata.co/api/token \
  -H "Content-Type: application/json" \
  -d '{ "username": "YOUR_USERNAME", "password": "YOUR_PASSWORD" }'
```

```json theme={null}
{
  "refresh": "eyJhbGciOi...",
  "access": "eyJhbGciOi..."
}
```

## Refresh the access token

When the access token expires, request a new one with the refresh token:

```bash theme={null}
curl -X POST https://testapi.kravata.co/api/token/refresh \
  -H "Content-Type: application/json" \
  -d '{ "refresh": "YOUR_REFRESH_TOKEN" }'
```

```json theme={null}
{ "access": "eyJhbGciOi..." }
```

When the refresh token also expires, request a new pair with `POST /api/token`.

## Authenticate your requests

```bash theme={null}
curl https://testapi.kravata.co/api/infoClient \
  -H "Authorization: Bearer YOUR_ACCESS_TOKEN"
```

<Info>
  Most endpoints also require your `clientId`, in the path (`/api/accounts/{clientId}`) or as a query parameter (`/api/ramps?clientId=...`). Get it from [Get Client Info](/business/api-reference/authentication/get-client-info).
</Info>

<Warning>
  Call the API only from your backend. Never expose your password or tokens in a browser or mobile app.
</Warning>
