curl --request POST \
--url https://api.malvo.io/connect_token \
--header 'Content-Type: application/json' \
--header 'X-API-KEY: <api-key>' \
--data '
{
"itemId": "a8f4f3e1-7b2c-4d4e-8f9a-0b1c2d3e4f5a",
"options": {
"clientUserId": "my-user-42",
"webhookUrl": "https://your.app/webhooks/malvo",
"oauthRedirectUri": "https://your.app/oauth/callback",
"avoidDuplicates": true,
"products": [
"ACCOUNTS",
"TRANSACTIONS"
]
}
}
'const options = {
method: 'POST',
headers: {'X-API-KEY': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
itemId: 'a8f4f3e1-7b2c-4d4e-8f9a-0b1c2d3e4f5a',
options: {
clientUserId: 'my-user-42',
webhookUrl: 'https://your.app/webhooks/malvo',
oauthRedirectUri: 'https://your.app/oauth/callback',
avoidDuplicates: true,
products: ['ACCOUNTS', 'TRANSACTIONS']
}
})
};
fetch('https://api.malvo.io/connect_token', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.malvo.io/connect_token"
payload = {
"itemId": "a8f4f3e1-7b2c-4d4e-8f9a-0b1c2d3e4f5a",
"options": {
"clientUserId": "my-user-42",
"webhookUrl": "https://your.app/webhooks/malvo",
"oauthRedirectUri": "https://your.app/oauth/callback",
"avoidDuplicates": True,
"products": ["ACCOUNTS", "TRANSACTIONS"]
}
}
headers = {
"X-API-KEY": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.malvo.io/connect_token",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'itemId' => 'a8f4f3e1-7b2c-4d4e-8f9a-0b1c2d3e4f5a',
'options' => [
'clientUserId' => 'my-user-42',
'webhookUrl' => 'https://your.app/webhooks/malvo',
'oauthRedirectUri' => 'https://your.app/oauth/callback',
'avoidDuplicates' => true,
'products' => [
'ACCOUNTS',
'TRANSACTIONS'
]
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-KEY: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"accessToken": "eyJ0eXAiOiJKV1QiLCJhbGciOi..."
}{
"code": 402,
"message": "Prepaid credits exhausted",
"codeDescription": "CREDITS_EXHAUSTED"
}{
"code": 403,
"message": "Missing or invalid authorization token"
}{
"code": 404,
"message": "Item not found",
"codeDescription": "ITEM_NOT_FOUND"
}{
"code": 500,
"message": "Internal server error",
"codeDescription": "INTERNAL_SERVER_ERROR"
}Emite um token com escopo do Connect Widget
Gera um accessToken de 30 minutos para dirigir o Connect Widget. Todos os campos são opcionais — um corpo {} retorna um token para criar um novo item. Passe itemId apenas para colocar o widget em modo de atualização de um item existente. ATENÇÃO: falha de autenticação aqui retorna 403 (não 401) — trate como “renove a apiKey via POST /auth e tente novamente”.
curl --request POST \
--url https://api.malvo.io/connect_token \
--header 'Content-Type: application/json' \
--header 'X-API-KEY: <api-key>' \
--data '
{
"itemId": "a8f4f3e1-7b2c-4d4e-8f9a-0b1c2d3e4f5a",
"options": {
"clientUserId": "my-user-42",
"webhookUrl": "https://your.app/webhooks/malvo",
"oauthRedirectUri": "https://your.app/oauth/callback",
"avoidDuplicates": true,
"products": [
"ACCOUNTS",
"TRANSACTIONS"
]
}
}
'const options = {
method: 'POST',
headers: {'X-API-KEY': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
itemId: 'a8f4f3e1-7b2c-4d4e-8f9a-0b1c2d3e4f5a',
options: {
clientUserId: 'my-user-42',
webhookUrl: 'https://your.app/webhooks/malvo',
oauthRedirectUri: 'https://your.app/oauth/callback',
avoidDuplicates: true,
products: ['ACCOUNTS', 'TRANSACTIONS']
}
})
};
fetch('https://api.malvo.io/connect_token', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.malvo.io/connect_token"
payload = {
"itemId": "a8f4f3e1-7b2c-4d4e-8f9a-0b1c2d3e4f5a",
"options": {
"clientUserId": "my-user-42",
"webhookUrl": "https://your.app/webhooks/malvo",
"oauthRedirectUri": "https://your.app/oauth/callback",
"avoidDuplicates": True,
"products": ["ACCOUNTS", "TRANSACTIONS"]
}
}
headers = {
"X-API-KEY": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.malvo.io/connect_token",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'itemId' => 'a8f4f3e1-7b2c-4d4e-8f9a-0b1c2d3e4f5a',
'options' => [
'clientUserId' => 'my-user-42',
'webhookUrl' => 'https://your.app/webhooks/malvo',
'oauthRedirectUri' => 'https://your.app/oauth/callback',
'avoidDuplicates' => true,
'products' => [
'ACCOUNTS',
'TRANSACTIONS'
]
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-KEY: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"accessToken": "eyJ0eXAiOiJKV1QiLCJhbGciOi..."
}{
"code": 402,
"message": "Prepaid credits exhausted",
"codeDescription": "CREDITS_EXHAUSTED"
}{
"code": 403,
"message": "Missing or invalid authorization token"
}{
"code": 404,
"message": "Item not found",
"codeDescription": "ITEM_NOT_FOUND"
}{
"code": 500,
"message": "Internal server error",
"codeDescription": "INTERNAL_SERVER_ERROR"
}Authorizations
Body
Corpo do connect_token. Todos os campos são opcionais; {} cria um token para um novo item.
Informe apenas para colocar o widget em modo de atualização de um item existente (re-auth / MFA / renovação de consentimento). Omita para criar um novo item.
"a8f4f3e1-7b2c-4d4e-8f9a-0b1c2d3e4f5a"
Opções de conexão por token, todas opcionais.
Show child attributes
Show child attributes
Response
Token do widget emitido com sucesso (TTL de 30 minutos).
Token com escopo do Connect Widget.
Token com TTL de 30 minutos para dirigir o Connect Widget e ler o único item que ele cria/atualiza.
"eyJ0eXAiOiJKV1QiLCJhbGciOi..."