Skip to main content

Authentication Overview

All ChainIT APIs are secured using OAuth 2.0, an industry-standard authorization framework that provides a robust, flexible, and auditable mechanism for granting application-level access to platform resources. Every API request must carry a valid, unexpired access token issued specifically for your organization and scoped to the permissions required for the operation.

Authentication Model​

ChainIT uses the OAuth 2.0 Client Credentials flow for server-to-server API integrations. This flow is designed for backend services and machine-to-machine communication where no end-user context is required. The client application authenticates using its own credentials — a client_id and client_secret — to obtain an access token that is then used to authorize API requests.

This approach ensures that:

  • Access tokens are never issued without a valid client identity verification.
  • Tokens are time-limited, reducing the risk of token leakage.
  • Each integration can be granted only the minimum set of permissions required.
  • Token issuance and usage are logged for audit purposes.

Obtaining an Access Token​

To obtain an access token, make a POST request to the token endpoint with your client credentials. The response includes the access token, its type, and the expiry duration in seconds.

Token Request​

POST /oauth/token
Content-Type: application/x-www-form-urlencoded

grant_type=client_credentials
&client_id=<<your_client_id>>
&client_secret=<<your_client_secret>>
&scope=<<requested_scopes>>

Token Response​

{
"status": 201,
"success": true,
"message": "Resource was successfully created.",
"data": {
"access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9....",
"token_type": "Bearer",
"expires_in": 86400
},
"metadata": {
"requestId": "297720578942849025",
"timestamp": "2026-02-13T11:28:37.488Z"
},
"details": {
"hint": "Used for POST requests when a new entity is created."
}
}

Response Fields​

FieldDescription
access_tokenThe token to include in subsequent API requests.
token_typeAlways Bearer. Use this prefix in the Authorization header.
expires_inToken validity period in seconds from the time of issuance. Typically 86400 seconds (24 hours).

Using the Access Token​

Include the access token in the Authorization header of every API request using the Bearer scheme:

GET /public-api/v1/accounts HTTP/1.1
Host: api.chainit.com
Authorization: Bearer eyJhbGciOiJSUzI1NiIsIn...
Content-Type: application/json

Important: Never include access tokens in URL query strings. Always transmit tokens via the Authorization header over HTTPS to prevent token exposure in server logs, browser history, or HTTP referrer headers.