API reference · Authentication
Get Access Token
- Method
- POST
- Route
-
/oauth/token - Base URL
https://ws.autorei.net- Token
- No token required
Opens this request in the public API documentation, the official source of the reference.
Description
Authenticates a platform user and returns the access_token used in all other API calls. It is the only endpoint that does not require a token — and the only one that carries its own Authorization header, with the fixed credential of the integration client, already filled in on the request.
Request body (form-urlencoded)
| Field | Type | Required | Description |
|---|---|---|---|
grant_type |
string | Yes | Always password. |
username |
string | Yes | Your user's e-mail on the CWS Platform. |
password |
string | Yes | Your user's password on the CWS Platform. |
scope |
string | No | read, write or trust. If you omit it, the token is born with all three (read write trust) — and any one of them authorizes all API routes. |
Business rules
Validity
The access_token is valid for 12 hours (expires_in arrives as 43199, in seconds). When it expires, authenticate again at this same URL.
How to send the token in the other calls
The header is Authorization: Bearer , with the prefix Bearer — without it the request is rejected with 401. In this collection this is already set up: this request saves the token in the access_token variable and the others inherit the collection's header, so you do not need to copy anything.
Response · 200
| Field | Type | Description |
|---|---|---|
access_token |
string | Access token for the next calls. |
token_type |
string | Always bearer. |
expires_in |
integer | Remaining seconds of validity of the access_token. |
scope |
string | Scopes granted, separated by space. |
Errors
| Code | When |
|---|---|
| 401 | Invalid user or password. The body carries error (invalid_grant) and the detail in error_description. |
| 401 on the other routes | Token missing, malformed or expired: {"error":"authorization header is invalid"}. Authenticate again and repeat the call. |
Example request
curl --request POST 'https://ws.autorei.net/oauth/token' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--header 'Authorization: Basic <credencial-do-cliente-de-integracao>' \
--data-urlencode 'scope=trust' \
--data-urlencode 'grant_type=password' \
--data-urlencode 'username=integracao@lojaexemplo.com.br' \
--data-urlencode 'password=sua-senha' The Authorization header in this example carries a placeholder instead of the integration client credential. The value is in the public collection: open this request in the collection.
Example responses
200Success — password authentication
{
"access_token": "1f7c9a04-3b52-4e18-9d61-2c8f5a0e7b43",
"token_type": "bearer",
"refresh_token": "a3d18e57-6c40-4f92-8ba7-19e35c72d068",
"expires_in": 43199,
"scope": "trust"
} Used in
- Use casesEcommerce ERP integration: the typical path through the API
- Use casesB2B customer portal: the typical path through the API
- Use casesB2B marketplace: the typical path through the API
- Use casesComplex retail and B2B2C: the typical path through the API
- Use casesB2B procurement and supplies: the typical path through the API
- Use casesGuided selling and counter sales: the typical path through the API
- Get startedEnvironments and base URL
- Get startedAuthentication
- Get startedErrors
Generated from the public API collection, published on 2026-09-04: api-docs.cws.digital.