Kravata assigns API credentials (apiKey and secretKey) to accepted customers after the onboarding and compliance review. You exchange them for a temporary access token and send that token in every request.
Get an access token
Call Client Login with your credentials:
The response contains the token (accessToken) and its validity in seconds (expiresIn). Store the token and reuse it until it expires instead of requesting a new one for every call.
Authenticate your requests
Send the token in the Authorization header of every other request:
When the token expires the API responds with 401. Request a new one with the same endpoint.
Call the API only from your backend. Your apiKey, secretKey and access tokens must never reach a browser or a mobile app.