Skip to content
platform

API reference · Authentication

Get Access Token

Method
POST
Route
/oauth/token
Base URL
https://ws.autorei.net
Token
No token required
Test in Postman

Opens this request in the public API documentation, the official source of the reference.

Description

Authenticates a platform user and returns the access_token used in all other API calls. It is the only endpoint that does not require a token — and the only one that carries its own Authorization header, with the fixed credential of the integration client, already filled in on the request.

Request body (form-urlencoded)

Field Type Required Description
grant_type string Yes Always password.
username string Yes Your user's e-mail on the CWS Platform.
password string Yes Your user's password on the CWS Platform.
scope string No read, write or trust. If you omit it, the token is born with all three (read write trust) — and any one of them authorizes all API routes.

Business rules

Validity

The access_token is valid for 12 hours (expires_in arrives as 43199, in seconds). When it expires, authenticate again at this same URL.

How to send the token in the other calls

The header is Authorization: Bearer , with the prefix Bearer — without it the request is rejected with 401. In this collection this is already set up: this request saves the token in the access_token variable and the others inherit the collection's header, so you do not need to copy anything.

Response · 200

Field Type Description
access_token string Access token for the next calls.
token_type string Always bearer.
expires_in integer Remaining seconds of validity of the access_token.
scope string Scopes granted, separated by space.

Errors

Code When
401 Invalid user or password. The body carries error (invalid_grant) and the detail in error_description.
401 on the other routes Token missing, malformed or expired: {"error":"authorization header is invalid"}. Authenticate again and repeat the call.

Example request

curl --request POST 'https://ws.autorei.net/oauth/token' \
  --header 'Content-Type: application/x-www-form-urlencoded' \
  --header 'Authorization: Basic <credencial-do-cliente-de-integracao>' \
  --data-urlencode 'scope=trust' \
  --data-urlencode 'grant_type=password' \
  --data-urlencode 'username=integracao@lojaexemplo.com.br' \
  --data-urlencode 'password=sua-senha'

The Authorization header in this example carries a placeholder instead of the integration client credential. The value is in the public collection: open this request in the collection.

Example responses

200Success — password authentication

{
  "access_token": "1f7c9a04-3b52-4e18-9d61-2c8f5a0e7b43",
  "token_type": "bearer",
  "refresh_token": "a3d18e57-6c40-4f92-8ba7-19e35c72d068",
  "expires_in": 43199,
  "scope": "trust"
}

Used in

Generated from the public API collection, published on 2026-09-04: api-docs.cws.digital.