Authentication Token
| Environment | API URL |
|---|---|
| MITE (TEST) | https://api.mite.pay360.com |
| LIVE | https://api.pay360.com |
There are multiple ways to get the token. The first is a server-to-server call to the Advanced Payments API, with the token then sent to the mobile app by your own API. However, if your backend is not ready yet, or you just want to test the functionality of the Mobile SDK, you can temporarily use our built-in method at com.accesspaysuite.mobilesdk.utils.AuthenticationHelper.
AuthenticationHelper must not go beyond the TEST/MITE environment: it requires the raw credentials (username, password) in order to generate an authentication token, and those cannot be completely and efficiently obfuscated to guarantee a secure environment for your app and credentials.Get authentication token (API)
To obtain an authentication token using the Advanced Payments API, make a POST request to the endpoint below. Replace {instId} with your actual installation identifier.
Customer payment
POST /acceptor/rest/authorisation/{instId}/authoriseClient{
"scopes": [
"MOBILE_CUSTOMER_PAYMENT"
],
"customerReference": "CUST_000001"
}curl -X POST "{targetEnvironmentPath}/acceptor/rest/authorisation/{instId}/authoriseClient" \
-H "Authorization: Basic base64(username:password)" \
-H "Content-Type: application/json" \
-d '{
"scopes": [
"MOBILE_CUSTOMER_PAYMENT"
],
"customerReference": "CUST_000001"
}'HTTP/1.1 200
{
"clientToken": "YOUR_CLIENT_TOKEN",
"status": "S100",
"message": "OK",
"expires": "2024-09-11T14:16:19.000Z"
}Guest payment
POST /acceptor/rest/authorisation/{instId}/authoriseClient{
"scopes": [
"MOBILE_GUEST_PAYMENT"
]
}curl -X POST "{targetEnvironmentPath}/acceptor/rest/authorisation/{instId}/authoriseClient" \
-H "Authorization: Basic base64(username:password)" \
-H "Content-Type: application/json" \
-d '{
"scopes": [
"MOBILE_GUEST_PAYMENT"
]
}'HTTP/1.1 200
{
"clientToken": "YOUR_CLIENT_TOKEN",
"status": "S100",
"message": "OK",
"expires": "2024-09-11T14:16:19.000Z"
}Customer payment with card management
POST /acceptor/rest/authorisation/{instId}/authoriseClient{
"scopes": [
"MOBILE_CUSTOMER_PAYMENT",
"MOBILE_CUSTOMER_MANAGE"
],
"customerReference": "my_customer_reference"
}curl -X POST "{targetEnvironmentPath}/acceptor/rest/authorisation/{instId}/authoriseClient" \
-H "Authorization: Basic base64(username:password)" \
-H "Content-Type: application/json" \
-d '{
"scopes": [
"MOBILE_CUSTOMER_PAYMENT",
"MOBILE_CUSTOMER_MANAGE"
],
"customerReference": "my_customer_reference"
}'HTTP/1.1 200
{
"clientToken": "YOUR_CLIENT_TOKEN",
"status": "S100",
"message": "OK",
"expires": "2024-09-11T14:16:19.000Z"
}The clientToken is what you pass to PaymentConfig. The customerReference should be unique to the specific customer; for guest customers it should be null, and the payment is processed as a guest user.
customerReference of the user whose saved cards you want to access.Get authentication token (Helper)
Using the Mobile SDK’s AuthenticationHelper class you can quickly test the token request. This approach is only recommended for debug and testing, as it requires your basic authentication pair to be present in the app.
/**
* Async Helper method to retrieve Authorization Credentials (Client Token) for
* Advanced Payments Platform (AP)
*
* The customer reference must be the unique reference of the customer and will
* be used to manage the customer's payment methods and other details.
*
* The customer reference can be null if the guestPayment flag is set to true.
*
* The guest payment flag is used to process the payment as a guest user.
* Making the payment as guest it will not store any customer details.
*
* @param environment The environment to use for the request
* @param instId The installation ID
* @param userName The API username
* @param password The API password
* @param customerReference The customer reference (nullable)
* @param guestPayment The guest payment flag (false/true)
* @param includeManageScope Include MOBILE_CUSTOMER_MANAGE scope for card management operations
*
* @return The Authentication Token (Client Token) as a string
*/
@Throws(AuthorizationException::class, CancellationException::class)
suspend fun requestAuthToken(
environment: Environment,
instId: String,
userName: String,
password: String,
customerReference: String?,
guestPayment: Boolean,
includeManageScope: Boolean = false
): String