3. Get your Access Token

All requests to Cabify API have to be authorized. This means that with the OAuth UUID and Secret of the integration you created in the previous step, you will have to generate an access token. All subsequent requests that you make to the API have to have a valid access token to authorize the request.

To get your Access Token token make the following POST request using your favorite HTTP client (curl example using sandbox environment):

curl -X POST -d "grant_type=client_credentials&client_id=OAUTH_UUID&client_secret=SECRET" https://cabify-sandbox.com/auth/api/authorization

The success response should be like this:

{
  "token_type": "Bearer",
  "expires_in": 2591999,
  "access_token":"1Lex4yzYz0M1NoMa-kfE1Uj3BdDd18"
}

IMPORTANT: The value of the key itself will only be shown once at the time of creation, so be sure to save it somewhere securely immediately.

📘

Why the parameter is called client_id

You send your integration's OAuth UUID in a parameter named client_id because that is the parameter name defined by the OAuth2 standard for a client credentials request.

This is not the same thing as your Cabify account's client_id, the value we send in the X-CABIFY-CLIENT-ID header and in data.client_id of every webhook. They are two different identifiers: the OAuth UUID identifies your integration and is a shared secret, while the account client_id identifies your Cabify account and is public. See Webhook Headers.

All requests (sandbox and production environments) should include an access token in an Authorization header

📘

Expiration time

Please note that access token expires for security reasons. You will have to renew it before it expires (see below).
expires_in field is in seconds, which is approximately 30 days.

Token Refresh

To refresh an access token you need to create a new token when the current one is about to expire, using the "expires_in" field obtained previously. All this logic should be implemented on the client's side.

Token Revocation

The Token Revocation extension defines a mechanism for clients to indicate to the authorization server that an access token is no longer needed. This is used to enable a "log out" feature in clients, allowing the authorization server to clean up any security credentials associated with the authorization.

To revoke an access token make a DELETE request such as this one:

curl -v -X DELETE
    --url 'https://cabify-sandbox.com/auth/api/authorization'
    --header 'authorization: Bearer THwi13of2EHnPsSdfYmrB7Q17P6soi'

You will get an HTTP 204 Code response if the operation is successful.


What’s Next

Did this page help you?