Create an access token | Moov Documentation
Create an access token
Create or refresh an access token.
Request
POST
/oauth2/token
Example CURL Request
curl -X POST "https://api.moov.io/oauth2/token" \
-H "Authorization: Bearer {token}" \
-H "X-Moov-Version: v2026.07.00" \
-d '{
"grant_type": "client_credentials"
}'
SDK Examples
JavaScript
import { Moov } from "@moovio/sdk";
const moov = new Moov({
security: {
username: "",
password: "",
},
});
async function run() {
const result = await moov.authentication.createAccessToken({
grantType: "client_credentials",
clientId: "5clTR_MdVrrkgxw2",
clientSecret: "dNC-hg7sVm22jc3g_Eogtyu0_1Mqh_4-",
scope: "/accounts.read /accounts.write",
refreshToken: "eyJhbGc0eSI6TQSIsImN0kpXVCIsImtp6IkpXVsImtpZC0a...",
});
console.log(result);
}
run();
PHP
declare(strict_types=1);
require 'vendor/autoload.php';
use Moov\MoovPhp;
use Moov\MoovPhp\Models\Components;
$sdk = MoovPhp\Moov::builder()
->setSecurity(
new Components\Security(
username: '',
password: '',
)
)
->build();
$request = new Components\AuthTokenRequest(
grantType: Components\GrantType::ClientCredentials,
clientId: '5clTR_MdVrrkgxw2',
clientSecret: 'dNC-hg7sVm22jc3g_Eogtyu0_1Mqh_4-',
scope: '/accounts.read /accounts.write',
refreshToken: 'eyJhbGc0eSI6TQSIsImN0kpXVCIsImtp6IkpXVsImtpZC0a...',
);
$response = $sdk->authentication->createToken(
request: $request
);
if ($response->authToken !== null) {
// handle response
}
Java
package hello.world;
import io.moov.sdk.Moov;
import io.moov.sdk.models.components.*;
import io.moov.sdk.models.errors.AuthTokenRequestError;
import io.moov.sdk.models.errors.GenericError;
import io.moov.sdk.models.operations.CreateAccessTokenResponse;
import java.lang.Exception;
public class Application {
public static void main(String[] args) throws GenericError, AuthTokenRequestError, Exception {
Moov sdk = Moov.builder()
.security(Security.builder()
.username("")
.password("")
.build())
.build();
AuthTokenRequest req = AuthTokenRequest.builder()
.grantType(GrantType.CLIENT_CREDENTIALS)
.clientId("5clTR_MdVrrkgxw2")
.clientSecret("dNC-hg7sVm22jc3g_Eogtyu0_1Mqh_4-")
.scope("/accounts.read /accounts.write")
.refreshToken("eyJhbGc0eSI6TQSIsImN0kpXVCIsImtp6IkpXVsImtpZC0a...")
.build();
CreateAccessTokenResponse res = sdk.authentication().createAccessToken()
.request(req)
.call();
if (res.authToken().isPresent()) {
System.out.println(res.authToken().get());
}
}
}
Python
from moovio_sdk import Moov
from moovio_sdk.models import components
with Moov(
security=components.Security(
username="",
password="",
),
) as moov:
res = moov.authentication.create_access_token(grant_type=components.GrantType.CLIENT_CREDENTIALS, client_id="5clTR_MdVrrkgxw2", client_secret="dNC-hg7sVm22jc3g_Eogtyu0_1Mqh_4-", scope="/accounts.read /accounts.write", refresh_token="eyJhbGc0eSI6TQSIsImN0kpXVCIsImtp6IkpXVsImtpZC0a...")
# Handle response
print(res)
Ruby
require 'moov_ruby'
Models = ::Moov::Models
s = ::Moov::Client.new(
security: Models::Components::Security.new(
username: '',
password: ''
)
)
req = Models::Components::AuthTokenRequest.new(
grant_type: Models::Components::GrantType::CLIENT_CREDENTIALS,
client_id: '5clTR_MdVrrkgxw2',
client_secret: 'dNC-hg7sVm22jc3g_Eogtyu0_1Mqh_4-',
scope: '/accounts.read /accounts.write',
refresh_token: 'eyJhbGc0eSI6TQSIsImN0kpXVCIsImtp6IkpXVsImtpZC0a...'
)
res = s.authentication.create_access_token(request: req)
unless res.auth_token.nil?
# handle response
end
C#
using Moov.Sdk;
using Moov.Sdk.Models.Components;
var sdk = new MoovClient(security: new Security() {
Username = "",
Password = "",
});
AuthTokenRequest req = new AuthTokenRequest() {
GrantType = GrantType.ClientCredentials,
ClientId = "5clTR_MdVrrkgxw2",
ClientSecret = "dNC-hg7sVm22jc3g_Eogtyu0_1Mqh_4-",
Scope = "/accounts.read /accounts.write",
RefreshToken = "eyJhbGc0eSI6TQSIsImN0kpXVCIsImtp6IkpXVsImtpZC0a...",
};
var res = await sdk.Authentication.CreateAccessTokenAsync(req);
// handle response
Response Examples
Successful Response
{
"token_type": "Bearer",
"access_token": "eyJhbGciOiJFZERTQSIsImN0eSI6IkpXVCIsImtpZCI6IkR...",
"refresh_token": "eyJhbGc0eSI6TQSIsImN0kpXVCIsImtp6IkpXVsImtpZC0a...",
"expires_in": 1736964352,
"scope": "/accounts.read /accounts.write"
}
Error Responses
Invalid Syntax
{
"error": "string"
}
Validation Failure
{
"scope": "string",
"refresh_token": "string"
}
Additional Information
- Set the
X-Moov-Versionheader tov2026.07.00for compatibility with the API described in this specification. - Common grant types include
client_credentialsandrefresh_token.