Troca credenciais de cliente por uma apiKey
curl --request POST \
--url https://api.malvo.io/auth \
--header 'Content-Type: application/json' \
--data '
{
"clientId": "b6e3a4c2-1234-4d5e-9f00-abcdefabcdef",
"clientSecret": "s3cr3t-opaque-string"
}
'const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
clientId: 'b6e3a4c2-1234-4d5e-9f00-abcdefabcdef',
clientSecret: 's3cr3t-opaque-string'
})
};
fetch('https://api.malvo.io/auth', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.malvo.io/auth"
payload = {
"clientId": "b6e3a4c2-1234-4d5e-9f00-abcdefabcdef",
"clientSecret": "s3cr3t-opaque-string"
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.malvo.io/auth",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'clientId' => 'b6e3a4c2-1234-4d5e-9f00-abcdefabcdef',
'clientSecret' => 's3cr3t-opaque-string'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"apiKey": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."
}
Auth
Troca credenciais de cliente por uma apiKey
Recebe clientId e clientSecret (emitidos no Dashboard, uso server-side apenas) e devolve uma apiKey com TTL de 2 horas. A apiKey é enviada no header X-API-KEY nas demais chamadas server-side. Esta operação NÃO exige header de autenticação.
POST
/
auth
Troca credenciais de cliente por uma apiKey
curl --request POST \
--url https://api.malvo.io/auth \
--header 'Content-Type: application/json' \
--data '
{
"clientId": "b6e3a4c2-1234-4d5e-9f00-abcdefabcdef",
"clientSecret": "s3cr3t-opaque-string"
}
'const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
clientId: 'b6e3a4c2-1234-4d5e-9f00-abcdefabcdef',
clientSecret: 's3cr3t-opaque-string'
})
};
fetch('https://api.malvo.io/auth', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.malvo.io/auth"
payload = {
"clientId": "b6e3a4c2-1234-4d5e-9f00-abcdefabcdef",
"clientSecret": "s3cr3t-opaque-string"
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.malvo.io/auth",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'clientId' => 'b6e3a4c2-1234-4d5e-9f00-abcdefabcdef',
'clientSecret' => 's3cr3t-opaque-string'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"apiKey": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."
}
Body
application/json
Response
apiKey emitida com sucesso (TTL de 2 horas).
apiKey emitida pelo endpoint de autenticação.
String opaca tipo JWT com TTL de 2 horas. Enviada como header X-API-KEY nas chamadas server-side.
Example:
"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."