Request a Vault access token
curl --request POST \
--url https://api.staging.payrails.io/token/auth \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.staging.payrails.io/token/auth"
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, headers=headers)
print(response.text)const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.staging.payrails.io/token/auth', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.staging.payrails.io/token/auth",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.staging.payrails.io/token/auth"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.staging.payrails.io/token/auth")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.staging.payrails.io/token/auth")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"access_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwiaWF0IjoxNTE2MjM5MDIyLCJleHAiOjM2MDB9.YLbew8qP_oOG8uY_lYHsLRv8YS5VzXW80gfNV4_KsbMD3R4xkndHjiz2k0YE58Vo2xyZoCI43_EUH0UZBI9pwAkG8kXTwWPNf95ILTvFQnAnnhWFDZUn2A0pB59bfDoEzhJI3_sI0KydqAOpUwM5kAzPWwKre0-da7ds27DngGdy0bQeaqk1TlHr6bHYrq1zn05lI-wm7V3BdHSxSIky-BED27yhDkXsdL55I9DW_-79cmpStRsoWRU2g4ZvOrgjZ5v7GSyALx7QBYEDOjoG4OLiva2jGJ8OI1OBP7iECiWTznpABdNvpwhsFvb4fVWe3pt_nPUM-8YNxNHVHNmheg",
"token_type": "Bearer",
"expires_in": 3600
}{
"errors": [
{
"id": "a24bc325-3929-4d9d-9c08-b3aa532685b7",
"code": "request.malformed",
"detail": "The request has malformed syntax",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#requestmalformed"
}
]
}{
"errors": [
{
"id": "a24bc325-3929-4d9d-9c08-b3aa532685b7",
"code": "request.unauthorized",
"detail": "The request lacks necessary credentials to perform the specified action",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#requestunauthorized"
}
]
}{
"errors": [
{
"id": "e7db22b3-914e-4975-928e-9edfb0885bea",
"code": "request.forbidden",
"detail": "The request credentials lack the required permissions to perform the specified action",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#requestforbidden"
}
]
}{
"errors": [
{
"id": "a24bc325-3929-4d9d-9c08-b3aa532685b7",
"code": "request.not-found",
"detail": "The requested resource was not found",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#requestnot-found"
}
]
}{
"errors": [
{
"id": "a24bc325-3929-4d9d-9c08-b3aa532685b7",
"code": "service.unavailable",
"detail": "The requested service is currently unavailable",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#serviceunavailable"
}
]
}Request a Vault access token
Exchange your Payrails access token for a Vault access token.
The Vault access token authenticates the tokenize and detokenize endpoints served on the Payrails Vault host, and grants only the operations your Payrails access token permits. The request body is empty, and these tokens are short-lived (the exact lifetime is returned in expires_in). Store it until it expires, then request a new one.
This endpoint is available by request and requires an approval by Payrails.
POST
https://api.staging.payrails.io
/
token
/
auth
Request a Vault access token
curl --request POST \
--url https://api.staging.payrails.io/token/auth \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.staging.payrails.io/token/auth"
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, headers=headers)
print(response.text)const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.staging.payrails.io/token/auth', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.staging.payrails.io/token/auth",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.staging.payrails.io/token/auth"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.staging.payrails.io/token/auth")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.staging.payrails.io/token/auth")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"access_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwiaWF0IjoxNTE2MjM5MDIyLCJleHAiOjM2MDB9.YLbew8qP_oOG8uY_lYHsLRv8YS5VzXW80gfNV4_KsbMD3R4xkndHjiz2k0YE58Vo2xyZoCI43_EUH0UZBI9pwAkG8kXTwWPNf95ILTvFQnAnnhWFDZUn2A0pB59bfDoEzhJI3_sI0KydqAOpUwM5kAzPWwKre0-da7ds27DngGdy0bQeaqk1TlHr6bHYrq1zn05lI-wm7V3BdHSxSIky-BED27yhDkXsdL55I9DW_-79cmpStRsoWRU2g4ZvOrgjZ5v7GSyALx7QBYEDOjoG4OLiva2jGJ8OI1OBP7iECiWTznpABdNvpwhsFvb4fVWe3pt_nPUM-8YNxNHVHNmheg",
"token_type": "Bearer",
"expires_in": 3600
}{
"errors": [
{
"id": "a24bc325-3929-4d9d-9c08-b3aa532685b7",
"code": "request.malformed",
"detail": "The request has malformed syntax",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#requestmalformed"
}
]
}{
"errors": [
{
"id": "a24bc325-3929-4d9d-9c08-b3aa532685b7",
"code": "request.unauthorized",
"detail": "The request lacks necessary credentials to perform the specified action",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#requestunauthorized"
}
]
}{
"errors": [
{
"id": "e7db22b3-914e-4975-928e-9edfb0885bea",
"code": "request.forbidden",
"detail": "The request credentials lack the required permissions to perform the specified action",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#requestforbidden"
}
]
}{
"errors": [
{
"id": "a24bc325-3929-4d9d-9c08-b3aa532685b7",
"code": "request.not-found",
"detail": "The requested resource was not found",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#requestnot-found"
}
]
}{
"errors": [
{
"id": "a24bc325-3929-4d9d-9c08-b3aa532685b7",
"code": "service.unavailable",
"detail": "The requested service is currently unavailable",
"docUrl": "https://docs.payrails.com/docs/resources/error-codes#serviceunavailable"
}
]
}Authorizations
BearerTokenBearerToken
You can use an OAuth2 JWT bearer token in the Authorization header of your API requests for supported endpoints: Authorization: Bearer <YOUR_JWT_HERE>.
These tokens are valid for 10 minutes and can be requested via the access token endpoint endpoint.
Last modified on October 7, 2026