| form | grant_type | |
| form | client_id | OAuth Client id |
| form | client_secret | OAuth Client id |
| form | username | |
| form | password | |
| form | scope | |
| form | mfa_token | Token obtained from the verification api |
{ "mfaToken": "59417a02-d35f-4e61-8230-50909f61b3dd", "password": "fin8@53y38!4rj", "clientId": "BoldAuthStaging", "clientSecret": "cw3JrFa5vYQGGcm46pABAsPS", "phoneNumber": "+40711111298" } |
| status | 200 | |
| header | Access-Control-Expose-Headers | authorization, content-type |
| header | Access-Control-Allow-Headers | authorization, content-type |
| header | Access-Control-Allow-Methods | GET, POST, DELETE, OPTIONS, PUT |
| header | Access-Control-Allow-Origin | * |
| header | Strict-Transport-Security | max-age=31536000; includeSubDomains |
| header | X-Frame-Options | SAMEORIGIN |
| header | X-Content-Type-Options | nosniff |
| header | X-XSS-Protection | 1; mode=block |
| header | Content-Security-Policy | default-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'none' |
| header | Referrer-Policy | no-referrer |
| header | Feature-Policy | self |
| header | Permissions-policy | interest-cohort=() |
{ "code": "2530c40b-0e57-4858-a92c-bbeb4f814a6c", "expiration": "2026-03-10T09:42:49.242594122Z", "accountId": 53, "accountCreated": false } | ||
| header | Content-Type | application/x-www-form-urlencoded |
| form | grant_type | authorization_code |
| form | code | 2530c40b-0e57-4858-a92c-bbeb4f814a6c |
| form | redirect_uri | boldsmartlock%3A%2F%2Fauth |
| form | client_id | BoldAuthStaging |
| form | client_secret | cw3JrFa5vYQGGcm46pABAsPS |
| status | 200 | |
| header | Access-Control-Expose-Headers | authorization, content-type |
| header | Access-Control-Allow-Headers | authorization, content-type |
| header | Access-Control-Allow-Methods | GET, POST, DELETE, OPTIONS, PUT |
| header | Access-Control-Allow-Origin | * |
| header | Strict-Transport-Security | max-age=31536000; includeSubDomains |
| header | X-Frame-Options | SAMEORIGIN |
| header | X-Content-Type-Options | nosniff |
| header | X-XSS-Protection | 1; mode=block |
| header | Content-Security-Policy | default-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'none' |
| header | Referrer-Policy | no-referrer |
| header | Feature-Policy | self |
| header | Permissions-policy | interest-cohort=() |
{ "access_token": "beab134e-6bb8-48ab-8778-c2b4acfcbc9f", "refresh_token": "63238090-ef22-4c70-a6d7-381477664235", "token_type": "Bearer", "expires_in": 86400, "account_id": 53 } | ||
| header | Content-Type | application/x-www-form-urlencoded |
| form | token | beab134e-6bb8-48ab-8778-c2b4acfcbc9f |
| form | token_type_hint | access_token |
| status | 200 | |
| header | Access-Control-Expose-Headers | authorization, content-type |
| header | Access-Control-Allow-Headers | authorization, content-type |
| header | Access-Control-Allow-Methods | GET, POST, DELETE, OPTIONS, PUT |
| header | Access-Control-Allow-Origin | * |
| header | Strict-Transport-Security | max-age=31536000; includeSubDomains |
| header | X-Frame-Options | SAMEORIGIN |
| header | X-Content-Type-Options | nosniff |
| header | X-XSS-Protection | 1; mode=block |
| header | Content-Security-Policy | default-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'none' |
| header | Referrer-Policy | no-referrer |
| header | Feature-Policy | self |
| header | Permissions-policy | interest-cohort=() |
{} | ||
| header | Content-Type | application/x-www-form-urlencoded |
| form | token | 17d67d53-4cf4-4947-8b82-013435e78ce5 |
| form | token_type_hint | access_token |
| status | 200 | |
| header | Access-Control-Expose-Headers | authorization, content-type |
| header | Access-Control-Allow-Headers | authorization, content-type |
| header | Access-Control-Allow-Methods | GET, POST, DELETE, OPTIONS, PUT |
| header | Access-Control-Allow-Origin | * |
| header | Strict-Transport-Security | max-age=31536000; includeSubDomains |
| header | X-Frame-Options | SAMEORIGIN |
| header | X-Content-Type-Options | nosniff |
| header | X-XSS-Protection | 1; mode=block |
| header | Content-Security-Policy | default-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'none' |
| header | Referrer-Policy | no-referrer |
| header | Feature-Policy | self |
| header | Permissions-policy | interest-cohort=() |
{} | ||
| header | Content-Type | application/x-www-form-urlencoded |
| form | token | PqAscz7EKcHXhPxK |
| form | token_type_hint | access_token |
| status | 200 | |
| header | Access-Control-Expose-Headers | authorization, content-type |
| header | Access-Control-Allow-Headers | authorization, content-type |
| header | Access-Control-Allow-Methods | GET, POST, DELETE, OPTIONS, PUT |
| header | Access-Control-Allow-Origin | * |
| header | Strict-Transport-Security | max-age=31536000; includeSubDomains |
| header | X-Frame-Options | SAMEORIGIN |
| header | X-Content-Type-Options | nosniff |
| header | X-XSS-Protection | 1; mode=block |
| header | Content-Security-Policy | default-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'none' |
| header | Referrer-Policy | no-referrer |
| header | Feature-Policy | self |
| header | Permissions-policy | interest-cohort=() |
{} | ||