Skip to navigation

Request authentication & authorization

Learn how to authenticate and authorize requests to the Invoice API.

OAUTH2 Authentication

The authentication flow consists of two main parts:

  1. Receiving a Bearer token from the OAUTH2 endpoint.
  2. Making a call to the Invoice API using this token.

Obtaining a Bearer token

First, you will need to obtain a ClientId and ClientSecret from our account or partner manager.

Using these secrets, you will need to obtain a Bearer token:

  1. Create a POST request to the endpoint https://auth.travel-data-api.bcdtravel.com/oauth2/token.

Headers

HeaderValue
AuthorizationBasic Base64Encode(ClientId:ClientSecret) — Client must pass its ClientId and ClientSecret in the authorization header through Basic HTTP authorization.
Content-Typeapplication/x-www-form-urlencoded

Body

ParameterValue
grant_typeclient_credentials
client_idYour ClientId value

After that, you will be issued an Access Bearer Token with a 1-hour lifetime.

Calling the Invoice API

In order to call the Invoice API using the token, create an Authorization header in the following format:

Authorization: Bearer <your_access_token>