> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://bcdtravel.ferndocs.com/itinerary/guides/introduction/authentication/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://bcdtravel.ferndocs.com/_mcp/server. # Authentication ## OAuth 2.0 The Itinerary API uses OAuth 2.0 — the industry-standard protocol for authorization. The OAuth 2.0 framework is a simple and secure way to implement a Unified Token Authentication mechanism within your application. Please visit [https://oauth.net/2/](https://oauth.net/2/) for more information. ## Exchanging credentials for the access token Before you can obtain an `accessToken`, you need to register your application with BCD Travel. You can do this by emailing [BCDTravelMarketplace@bcdtravel.com](mailto:BCDTravelMarketplace@bcdtravel.com) or by contacting your Account Manager. Once you have registered an application, you will receive a `client_id`, `client_secret` and the `URI Endpoint` for the Itinerary API. * **`client_id`** — A unique identifier for your application. * **`client_secret`** — Your application's password. * **`URI Endpoint`** — The URI for initiating all new connections to the Itinerary API. ## Client credentials grant Use the `application/x-www-form-urlencoded` content type. ``` [POST] https://auth.travel-data-api.bcdtravel.com/oauth2/token ``` ### Request parameters | Name | Type | Description | | --------------- | ------ | ---------------------------------------------------------------------------------------------------------------------------------------------------- | | `client_id` | string | **Required.** `client_id` supplied by BCD. | | `client_secret` | string | **Required.** `client_secret` supplied by BCD. | | `grant_type` | string | **Required.** Specify which grant type you expect the OAuth 2.0 service to process. For client credentials grant, the value is `client_credentials`. | ### Example request ```bash curl -X POST 'https://auth.travel-data-api.bcdtravel.com/oauth2/token' \ --header 'Content-Type: application/x-www-form-urlencoded' \ --data-urlencode 'client_id=your_client_id' \ --data-urlencode 'grant_type=client_credentials' \ --data-urlencode 'client_secret=your_client_secret' ``` ### Example response ```json { "access_token": "TOKEN", "expires_in": 3600, "token_type": "Bearer" } ``` ## Calling the API with the access token Once you have the `accessToken`, supply it in an `Authorization` header in the form of `Authorization: Bearer accessToken` when making an HTTPS call to the Itinerary API. ## Access token expiration Access tokens have a one-hour lifetime. In order to obtain a fresh `accessToken`, you need to `POST` to the auth endpoint using your `client_id` and `client_secret` and obtain a new token. > Learn how to authenticate requests to the Itinerary API using OAuth 2.0.