Exchange Refresh Token for Access Token
curl --request POST \
--url https://your-syteca-host/SytecaACB/get_access_token \
--header 'Content-Type: application/json' \
--data '
{
"refreshToken": "<string>"
}
'import requests
url = "https://your-syteca-host/SytecaACB/get_access_token"
payload = { "refreshToken": "<string>" }
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({refreshToken: '<string>'})
};
fetch('https://your-syteca-host/SytecaACB/get_access_token', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://your-syteca-host/SytecaACB/get_access_token",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'refreshToken' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://your-syteca-host/SytecaACB/get_access_token"
payload := strings.NewReader("{\n \"refreshToken\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://your-syteca-host/SytecaACB/get_access_token")
.header("Content-Type", "application/json")
.body("{\n \"refreshToken\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://your-syteca-host/SytecaACB/get_access_token")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"refreshToken\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"accessToken": "<string>",
"expires_in": 123
}{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}Endpoints
Get Access Token
Syteca ACB REST API endpoint to exchange a Refresh Token for a short-lived Access Token. The first call every API consumer makes.
POST
/
get_access_token
Exchange Refresh Token for Access Token
curl --request POST \
--url https://your-syteca-host/SytecaACB/get_access_token \
--header 'Content-Type: application/json' \
--data '
{
"refreshToken": "<string>"
}
'import requests
url = "https://your-syteca-host/SytecaACB/get_access_token"
payload = { "refreshToken": "<string>" }
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({refreshToken: '<string>'})
};
fetch('https://your-syteca-host/SytecaACB/get_access_token', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://your-syteca-host/SytecaACB/get_access_token",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'refreshToken' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://your-syteca-host/SytecaACB/get_access_token"
payload := strings.NewReader("{\n \"refreshToken\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://your-syteca-host/SytecaACB/get_access_token")
.header("Content-Type", "application/json")
.body("{\n \"refreshToken\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://your-syteca-host/SytecaACB/get_access_token")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"refreshToken\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"accessToken": "<string>",
"expires_in": 123
}{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}{
"status": 123,
"message": "<string>"
}Exchanges a Refresh Token for a short-lived Access Token. This is the first call every ACB API consumer makes — the returned Access Token authenticates subsequent calls to other endpoints. When the Access Token expires, call this endpoint again with the same Refresh Token.
This is one of the two old endpoints (pre-v1.3). Authentication uses the Refresh Token in the request body — there’s no
Authorization header on this call. Subsequent endpoints use the returned Access Token in the Authorization header (new endpoints) or in the request body (the other old endpoint, get_secret_details).For ACB deployments updated from a version prior to 1.2, switch to the
https://{hostname}/EkranACB server in the Playground.Where to get the Refresh Token
The Refresh Token comes from the Application Account Settings section of a Management Tool user — see Set up user account.Rate limit
5 requests per minute per Refresh Token. Consumers should cache the Access Token for its fullexpires_in lifetime rather than re-requesting on every call.
Errors
See Status codes. Common errors:- 401 Unauthorized — invalid or expired Refresh Token. Verify the token, and check whether the user’s external-app toggle was disabled.
- 403 Forbidden — the request originates from an IP not in the user’s IP Address restriction.
- 429 Too Many Requests — rate limit exceeded.
Related
Set up user account
Where to get the Refresh Token.
API reference
Status codes, rate limiting, conventions.
Get secret details (old)
Old retrieval endpoint using Access Token in body.
Get secret credentials (new)
New retrieval endpoint using Authorization header.
Body
application/json
Refresh Token from the user's Application Account Settings in the Management Tool.