Cards & Wallets · Mobile SDK

Authentication Token

EnvironmentAPI URL
MITE (TEST)https://api.mite.pay360.com
LIVEhttps://api.pay360.com

There are multiple ways to get the token. The first is a server-to-server call to the Advanced Payments API, with the token then sent to the mobile app by your own API. However, if your backend is not ready yet, or you just want to test the functionality of the Mobile SDK, you can temporarily use our built-in method at com.accesspaysuite.mobilesdk.utils.AuthenticationHelper.

The use of the AuthenticationHelper must not go beyond the TEST/MITE environment: it requires the raw credentials (username, password) in order to generate an authentication token, and those cannot be completely and efficiently obfuscated to guarantee a secure environment for your app and credentials.

Get authentication token (API)

To obtain an authentication token using the Advanced Payments API, make a POST request to the endpoint below. Replace {instId} with your actual installation identifier.

Customer payment
EndpointDefinition
POST /acceptor/rest/authorisation/{instId}/authoriseClient
Request body
{
    "scopes": [
        "MOBILE_CUSTOMER_PAYMENT"
    ],
    "customerReference": "CUST_000001"
}
cURL
curl -X POST "{targetEnvironmentPath}/acceptor/rest/authorisation/{instId}/authoriseClient" \
  -H "Authorization: Basic base64(username:password)" \
  -H "Content-Type: application/json" \
  -d '{
    "scopes": [
        "MOBILE_CUSTOMER_PAYMENT"
    ],
    "customerReference": "CUST_000001"
}'
Response
HTTP/1.1 200

{
    "clientToken": "YOUR_CLIENT_TOKEN",
    "status": "S100",
    "message": "OK",
    "expires": "2024-09-11T14:16:19.000Z"
}
Guest payment
EndpointDefinition
POST /acceptor/rest/authorisation/{instId}/authoriseClient
Request body
{
    "scopes": [
        "MOBILE_GUEST_PAYMENT"
    ]
}
cURL
curl -X POST "{targetEnvironmentPath}/acceptor/rest/authorisation/{instId}/authoriseClient" \
  -H "Authorization: Basic base64(username:password)" \
  -H "Content-Type: application/json" \
  -d '{
    "scopes": [
        "MOBILE_GUEST_PAYMENT"
    ]
}'
Response
HTTP/1.1 200

{
    "clientToken": "YOUR_CLIENT_TOKEN",
    "status": "S100",
    "message": "OK",
    "expires": "2024-09-11T14:16:19.000Z"
}
Customer payment with card management
EndpointDefinition
POST /acceptor/rest/authorisation/{instId}/authoriseClient
Request body
{
    "scopes": [
        "MOBILE_CUSTOMER_PAYMENT",
        "MOBILE_CUSTOMER_MANAGE"
    ],
    "customerReference": "my_customer_reference"
}
cURL
curl -X POST "{targetEnvironmentPath}/acceptor/rest/authorisation/{instId}/authoriseClient" \
  -H "Authorization: Basic base64(username:password)" \
  -H "Content-Type: application/json" \
  -d '{
    "scopes": [
        "MOBILE_CUSTOMER_PAYMENT",
        "MOBILE_CUSTOMER_MANAGE"
    ],
    "customerReference": "my_customer_reference"
}'
Response
HTTP/1.1 200

{
    "clientToken": "YOUR_CLIENT_TOKEN",
    "status": "S100",
    "message": "OK",
    "expires": "2024-09-11T14:16:19.000Z"
}

The clientToken is what you pass to PaymentConfig. The customerReference should be unique to the specific customer; for guest customers it should be null, and the payment is processed as a guest user.

To access the Card Management page you need a token with the MOBILE_CUSTOMER_MANAGE scope and the customerReference of the user whose saved cards you want to access.

Get authentication token (Helper)

Using the Mobile SDK’s AuthenticationHelper class you can quickly test the token request. This approach is only recommended for debug and testing, as it requires your basic authentication pair to be present in the app.

Kotlin
/**
* Async Helper method to retrieve Authorization Credentials (Client Token) for
* Advanced Payments Platform (AP)
*
* The customer reference must be the unique reference of the customer and will
* be used to manage the customer's payment methods and other details.
*
* The customer reference can be null if the guestPayment flag is set to true.
*
* The guest payment flag is used to process the payment as a guest user.
* Making the payment as guest it will not store any customer details.
*
* @param environment The environment to use for the request
* @param instId The installation ID
* @param userName The API username
* @param password The API password
* @param customerReference The customer reference (nullable)
* @param guestPayment The guest payment flag (false/true)
* @param includeManageScope Include MOBILE_CUSTOMER_MANAGE scope for card management operations
*
* @return The Authentication Token (Client Token) as a string
*/
@Throws(AuthorizationException::class, CancellationException::class)
suspend fun requestAuthToken(
  environment: Environment,
  instId: String,
  userName: String,
  password: String,
  customerReference: String?,
  guestPayment: Boolean,
  includeManageScope: Boolean = false
): String