Appearance
Platform authentication
Authentication depends on the API you call. Platform user credentials, card partner tokens, and onboarding tokens have different scopes.
| API | Credential | Guide |
|---|---|---|
| Platform GraphQL | User access token or authenticated platform session | User requests |
| Cards partner GraphQL | Partner API token and HMAC signature | Partner authentication |
| Platform REST | Depends on the route | REST authentication |
User requests
Send the platform user's access token in the Authorization header:
bash
curl https://api.agiodigital.com/graphql \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_USER_ACCESS_TOKEN" \
--data '{"query":"query ConnectionCheck { __typename }"}'The platform uses the authenticated user's roles and organization access when authorizing operations. Browser clients can also use an authenticated platform session; see browser sessions.
Card partners
Call /partner/cards/graphql with the partner token and required signature headers. Follow partner authentication for the exact bytes to sign and a working server-side example.
Failures
Check both the HTTP status and the GraphQL errors array. An accepted HTTP request can still fail authorization at the GraphQL operation. Use the error code returned by the endpoint when deciding whether to sign in again, request access, or retry.