> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://bcdtravel.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://bcdtravel.ferndocs.com/_mcp/server.

# Authentication

## OAuth 2.0

The Itinerary API uses OAuth 2.0 — the industry-standard protocol for authorization. The OAuth 2.0 framework is a simple and secure way to implement a Unified Token Authentication mechanism within your application. Please visit [https://oauth.net/2/](https://oauth.net/2/) for more information.

## Exchanging credentials for the access token

Before you can obtain an `accessToken`, you need to register your application with BCD Travel. You can do this by emailing [BCDTravelMarketplace@bcdtravel.com](mailto:BCDTravelMarketplace@bcdtravel.com) or by contacting your Account Manager. Once you have registered an application, you will receive a `client_id`, `client_secret` and the `URI Endpoint` for the Itinerary API.

* **`client_id`** — A unique identifier for your application.
* **`client_secret`** — Your application's password.
* **`URI Endpoint`** — The URI for initiating all new connections to the Itinerary API.

## Client credentials grant

Use the `application/x-www-form-urlencoded` content type.

```
[POST] https://auth.travel-data-api.bcdtravel.com/oauth2/token
```

### Request parameters

| Name            | Type   | Description                                                                                                                                          |
| --------------- | ------ | ---------------------------------------------------------------------------------------------------------------------------------------------------- |
| `client_id`     | string | **Required.** `client_id` supplied by BCD.                                                                                                           |
| `client_secret` | string | **Required.** `client_secret` supplied by BCD.                                                                                                       |
| `grant_type`    | string | **Required.** Specify which grant type you expect the OAuth 2.0 service to process. For client credentials grant, the value is `client_credentials`. |

### Example request

```bash
curl -X POST 'https://auth.travel-data-api.bcdtravel.com/oauth2/token' \
  --header 'Content-Type: application/x-www-form-urlencoded' \
  --data-urlencode 'client_id=your_client_id' \
  --data-urlencode 'grant_type=client_credentials' \
  --data-urlencode 'client_secret=your_client_secret'
```

### Example response

```json
{
  "access_token": "TOKEN",
  "expires_in": 3600,
  "token_type": "Bearer"
}
```

## Calling the API with the access token

Once you have the `accessToken`, supply it in an `Authorization` header in the form of `Authorization: Bearer accessToken` when making an HTTPS call to the Itinerary API.

## Access token expiration

Access tokens have a one-hour lifetime. In order to obtain a fresh `accessToken`, you need to `POST` to the auth endpoint using your `client_id` and `client_secret` and obtain a new token.