Create an access token | Moov Documentation

Create an access token

Create or refresh an access token.

Request to Create Token

POST
/oauth2/token

cURL Example

curl -X POST "https://api.moov.io/oauth2/token" \
  -H "Authorization: Bearer {token}" \
  -H "X-Moov-Version: v2026.04.00" \
  -d '{
  "grant_type": "client_credentials"
}'

TypeScript Example

import { Moov } from "@moovio/sdk";

const moov = new Moov({
  security: {
    username: "",
    password: "",
  },
});

async function run() {
  const result = await moov.authentication.createAccessToken({
    grantType: "client_credentials",
    clientId: "5clTR_MdVrrkgxw2",
    clientSecret: "dNC-hg7sVm22jc3g_Eogtyu0_1Mqh_4-",
    scope: "/accounts.read /accounts.write",
    refreshToken: "eyJhbGc0eSI6TQSIsImN0kpXVCIsImtp6IkpXVsImtpZC0a...",
  });

console.log(result);
}

run();

PHP Example

declare(strict_types=1);

require 'vendor/autoload.php';

use Moov\MoovPhp;
use Moov\MoovPhp\Models\Components;

$sdk = MoovPhp\Moov::builder()
    ->setSecurity(
        new Components\Security(
            username: '',
            password: '',
        )
    )
    ->build();

$request = new Components\AuthTokenRequest(
    grantType: Components\GrantType::ClientCredentials,
    clientId: '5clTR_MdVrrkgxw2',
    clientSecret: 'dNC-hg7sVm22jc3g_Eogtyu0_1Mqh_4-',
    scope: '/accounts.read /accounts.write',
    refreshToken: 'eyJhbGc0eSI6TQSIsImN0kpXVCIsImtp6IkpXVsImtpZC0a...',
);

$response = $sdk->authentication->createToken(
    request: $request
);

if ($response->authToken !== null) {
    // handle response
}

Java Example

package hello.world;

import io.moov.sdk.Moov;
import io.moov.sdk.models.components.*;
import io.moov.sdk.models.errors.AuthTokenRequestError;
import io.moov.sdk.models.errors.GenericError;
import io.moov.sdk.models.operations.CreateAccessTokenResponse;
import java.lang.Exception;

public class Application {

public static void main(String[] args) throws GenericError, AuthTokenRequestError, Exception {

Moov sdk = Moov.builder()
                .security(Security.builder()
                    .username("")
                    .password("")
                    .build())
            .build();

AuthTokenRequest req = AuthTokenRequest.builder()
                .grantType(GrantType.CLIENT_CREDENTIALS)
                .clientId("5clTR_MdVrrkgxw2")
                .clientSecret("dNC-hg7sVm22jc3g_Eogtyu0_1Mqh_4-")
                .scope("/accounts.read /accounts.write")
                .refreshToken("eyJhbGc0eSI6TQSIsImN0kpXVCIsImtp6IkpXVsImtpZC0a...")
                .build();

CreateAccessTokenResponse res = sdk.authentication().createAccessToken()
                .request(req)
                .call();

if (res.authToken().isPresent()) {
            System.out.println(res.authToken().get());
        }
    }
}

Python Example

from moovio_sdk import Moov
from moovio_sdk.models import components

with Moov(
    security=components.Security(
        username="",
        password="",
    ),
) as moov:

res = moov.authentication.create_access_token(grant_type=components.GrantType.CLIENT_CREDENTIALS, client_id="5clTR_MdVrrkgxw2", client_secret="dNC-hg7sVm22jc3g_Eogtyu0_1Mqh_4-", scope="/accounts.read /accounts.write", refresh_token="eyJhbGc0eSI6TQSIsImN0kpXVCIsImtp6IkpXVsImtpZC0a...")

# Handle response
    print(res)

Ruby Example

require 'moov_ruby'

Models = ::Moov::Models
s = ::Moov::Client.new(
  security: Models::Components::Security.new(
    username: '',
    password: ''
  )
)

req = Models::Components::AuthTokenRequest.new(
  grant_type: Models::Components::GrantType::CLIENT_CREDENTIALS,
  client_id: '5clTR_MdVrrkgxw2',
  client_secret: 'dNC-hg7sVm22jc3g_Eogtyu0_1Mqh_4-',
  scope: '/accounts.read /accounts.write',
  refresh_token: 'eyJhbGc0eSI6TQSIsImN0kpXVCIsImtp6IkpXVsImtpZC0a...'
)
res = s.authentication.create_access_token(request: req)

unless res.auth_token.nil?
  # handle response
end

C# Example

using Moov.Sdk;
using Moov.Sdk.Models.Components;

var sdk = new MoovClient(security: new Security() {
    Username = "",
    Password = "",
});

AuthTokenRequest req = new AuthTokenRequest() {
    GrantType = GrantType.ClientCredentials,
    ClientId = "5clTR_MdVrrkgxw2",
    ClientSecret = "dNC-hg7sVm22jc3g_Eogtyu0_1Mqh_4-",
    Scope = "/accounts.read /accounts.write",
    RefreshToken = "eyJhbGc0eSI6TQSIsImN0kpXVCIsImtp6IkpXVsImtpZC0a...",
};

var res = await sdk.Authentication.CreateAccessTokenAsync(req);

// handle response

Response Examples

Successful Response

{
  "token_type": "Bearer",
  "access_token": "eyJhbGciOiJFZERTQSIsImN0eSI6IkpXVCIsImtpZCI6IkR...",
  "refresh_token": "eyJhbGc0eSI6TQSIsImN0kpXVCIsImtp6IkpXVsImtpZC0a...",
  "expires_in": 1736964352,
  "scope": "/accounts.read /accounts.write"
}

Error Responses

Error: Invalid Request

{
  "error": "string"
}

Error: Validation Failed

{
  "scope": "string",
  "refresh_token": "string"
}

Additional Notes

Possible Grant Types: