> ## Documentation Index
> Fetch the complete documentation index at: https://docs-api.kravata.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Client Login

> Obtains a temporary access token using the `apiKey` and `secretKey` issued by Kravata during onboarding.

#### Request Body

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| apiKey | string | Yes | Your API key. |
| secretKey | string | Yes | Your secret key. |

#### Response

| Field | Description |
| --- | --- |
| accessToken | Token to send as `Authorization: Bearer <accessToken>` in every other request. |
| expiresIn | Validity of the token, in seconds. When it expires, call this endpoint again. |

The Postman test script stores the token in the `access_token` collection variable automatically.

#### Production

In production, call `https://partners-api.kravata.co/api/v1/client/token` presenting your mTLS certificate:

```bash
curl -X POST https://partners-api.kravata.co/api/v1/client/token \
  --cert client.crt --key client.key \
  -H "Content-Type: application/json" \
  -d '{"apiKey": "<apiKey>", "secretKey": "<secretKey>"}'
```

Request the certificate (`client.crt`) and private key (`client.key`) from your Kravata point of contact.



## OpenAPI

````yaml /stack/openapi.json post /api/v1/client/token
openapi: 3.1.0
info:
  title: Kravata Stack API
  version: '2.0'
  description: >-
    Kravata Stack API: users, accounts, custody wallets, liquidity ramps and
    fiat payments.
servers:
  - url: https://test-api-kore.kravata.co
    description: Test
  - url: https://partners-api.kravata.co
    description: Production (mTLS + IP allowlist)
security:
  - bearerAuth: []
tags:
  - name: Authentication
  - name: Users
  - name: Accounts
  - name: Earn
  - name: Custody
  - name: Liquidity Ramps
  - name: Payments
  - name: Webhooks
paths:
  /api/v1/client/token:
    post:
      tags:
        - Authentication
      summary: Client Login
      description: >-
        Obtains a temporary access token using the `apiKey` and `secretKey`
        issued by Kravata during onboarding.


        #### Request Body


        | Field | Type | Required | Description |

        | --- | --- | --- | --- |

        | apiKey | string | Yes | Your API key. |

        | secretKey | string | Yes | Your secret key. |


        #### Response


        | Field | Description |

        | --- | --- |

        | accessToken | Token to send as `Authorization: Bearer <accessToken>`
        in every other request. |

        | expiresIn | Validity of the token, in seconds. When it expires, call
        this endpoint again. |


        The Postman test script stores the token in the `access_token`
        collection variable automatically.


        #### Production


        In production, call
        `https://partners-api.kravata.co/api/v1/client/token` presenting your
        mTLS certificate:


        ```bash

        curl -X POST https://partners-api.kravata.co/api/v1/client/token \
          --cert client.crt --key client.key \
          -H "Content-Type: application/json" \
          -d '{"apiKey": "<apiKey>", "secretKey": "<secretKey>"}'
        ```


        Request the certificate (`client.crt`) and private key (`client.key`)
        from your Kravata point of contact.
      operationId: client-login
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                apiKey:
                  type: string
                secretKey:
                  type: string
            example:
              apiKey: '{{api_key}}'
              secretKey: '{{secret_key}}'
      responses:
        '200':
          description: Successful response
      security: []
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: Access token from POST /api/v1/client/token.

````