Skip to navigation

Authentication

Learn how to authenticate requests to the Itinerary API using OAuth 2.0.

OAuth 2.0

The Itinerary API uses OAuth 2.0 — the industry-standard protocol for authorization. The OAuth 2.0 framework is a simple and secure way to implement a Unified Token Authentication mechanism within your application. Please visit https://oauth.net/2/ for more information.

Exchanging credentials for the access token

Before you can obtain an accessToken, you need to register your application with BCD Travel. You can do this by emailing BCDTravelMarketplace@bcdtravel.com or by contacting your Account Manager. Once you have registered an application, you will receive a client_id, client_secret and the URI Endpoint for the Itinerary API.

  • client_id — A unique identifier for your application.
  • client_secret — Your application’s password.
  • URI Endpoint — The URI for initiating all new connections to the Itinerary API.

Client credentials grant

Use the application/x-www-form-urlencoded content type.

[POST] https://auth.travel-data-api.bcdtravel.com/oauth2/token

Request parameters

NameTypeDescription
client_idstringRequired. client_id supplied by BCD.
client_secretstringRequired. client_secret supplied by BCD.
grant_typestringRequired. Specify which grant type you expect the OAuth 2.0 service to process. For client credentials grant, the value is client_credentials.

Example request

curl -X POST 'https://auth.travel-data-api.bcdtravel.com/oauth2/token' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode 'client_id=your_client_id' \
--data-urlencode 'grant_type=client_credentials' \
--data-urlencode 'client_secret=your_client_secret'

Example response

{
"access_token": "TOKEN",
"expires_in": 3600,
"token_type": "Bearer"
}

Calling the API with the access token

Once you have the accessToken, supply it in an Authorization header in the form of Authorization: Bearer accessToken when making an HTTPS call to the Itinerary API.

Access token expiration

Access tokens have a one-hour lifetime. In order to obtain a fresh accessToken, you need to POST to the auth endpoint using your client_id and client_secret and obtain a new token.