3. Get your Access Token
All requests to Cabify API have to be authorized. This means that with the OAuth UUID and Secret of the integration you created in the previous step, you will have to generate an access token. All subsequent requests that you make to the API have to have a valid access token to authorize the request.
To get your Access Token token make the following POST request using your favorite HTTP client (curl example using sandbox environment):
curl -X POST -d "grant_type=client_credentials&client_id=OAUTH_UUID&client_secret=SECRET" https://cabify-sandbox.com/auth/api/authorizationThe success response should be like this:
{
"token_type": "Bearer",
"expires_in": 2591999,
"access_token":"1Lex4yzYz0M1NoMa-kfE1Uj3BdDd18"
}IMPORTANT: The value of the key itself will only be shown once at the time of creation, so be sure to save it somewhere securely immediately.
Why the parameter is calledclient_idYou send your integration's OAuth UUID in a parameter named
client_idbecause that is the parameter name defined by the OAuth2 standard for a client credentials request.This is not the same thing as your Cabify account's
client_id, the value we send in theX-CABIFY-CLIENT-IDheader and indata.client_idof every webhook. They are two different identifiers: the OAuth UUID identifies your integration and is a shared secret, while the accountclient_ididentifies your Cabify account and is public. See Webhook Headers.
All requests (sandbox and production environments) should include an access token in an Authorization header
Expiration timePlease note that access token expires for security reasons. You will have to renew it before it expires (see below).
expires_infield is in seconds, which is approximately 30 days.
Token Refresh
To refresh an access token you need to create a new token when the current one is about to expire, using the "expires_in" field obtained previously. All this logic should be implemented on the client's side.
Token Revocation
The Token Revocation extension defines a mechanism for clients to indicate to the authorization server that an access token is no longer needed. This is used to enable a "log out" feature in clients, allowing the authorization server to clean up any security credentials associated with the authorization.
To revoke an access token make a DELETE request such as this one:
curl -v -X DELETE
--url 'https://cabify-sandbox.com/auth/api/authorization'
--header 'authorization: Bearer THwi13of2EHnPsSdfYmrB7Q17P6soi'You will get an HTTP 204 Code response if the operation is successful.
Updated 14 days ago
