Skip to content

Platform authentication ​

Authentication depends on the API you call. Platform user credentials, card partner tokens, and onboarding tokens have different scopes.

APICredentialGuide
Platform GraphQLUser access token or authenticated platform sessionUser requests
Cards partner GraphQLPartner API token and HMAC signaturePartner authentication
Platform RESTDepends on the routeREST authentication

User requests ​

Send the platform user's access token in the Authorization header:

bash
curl https://api.agiodigital.com/graphql \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer YOUR_USER_ACCESS_TOKEN" \
  --data '{"query":"query ConnectionCheck { __typename }"}'

The platform uses the authenticated user's roles and organization access when authorizing operations. Browser clients can also use an authenticated platform session; see browser sessions.

Card partners ​

Call /partner/cards/graphql with the partner token and required signature headers. Follow partner authentication for the exact bytes to sign and a working server-side example.

Failures ​

Check both the HTTP status and the GraphQL errors array. An accepted HTTP request can still fail authorization at the GraphQL operation. Use the error code returned by the endpoint when deciding whether to sign in again, request access, or retry.