| form | grant_type | |
| form | client_id | OAuth Client id |
| form | client_secret | OAuth Client id |
| form | username | |
| form | password | |
| form | scope | |
| form | mfa_token | Token obtained from the verification api |
{ "mfaToken": "f7a4ecfb-56b9-4cc0-adcf-d3cdc4f4e3fe", "password": "fin8@53y38!4rj", "clientId": "BoldAuthStaging", "clientSecret": "cw3JrFa5vYQGGcm46pABAsPS", "phoneNumber": "+40711111298" } |
| status | 200 | |
| header | Access-Control-Expose-Headers | authorization, content-type |
| header | Access-Control-Allow-Headers | authorization, content-type |
| header | Access-Control-Allow-Methods | GET, POST, DELETE, OPTIONS, PUT |
| header | Access-Control-Allow-Origin | * |
| header | Strict-Transport-Security | max-age=31536000; includeSubDomains |
| header | X-Frame-Options | SAMEORIGIN |
| header | X-Content-Type-Options | nosniff |
| header | X-XSS-Protection | 1; mode=block |
| header | Content-Security-Policy | default-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'none' |
| header | Referrer-Policy | no-referrer |
| header | Feature-Policy | self |
| header | Permissions-policy | interest-cohort=() |
{ "code": "711ca5e1-7155-4b5c-b11b-bd2528b96ffe", "expiration": "2026-08-21T15:13:25.858626921Z", "accountId": 1, "accountCreated": false, "registered": true, "emailAddress": "sesam@example.com" } | ||
| header | Content-Type | application/x-www-form-urlencoded |
| form | grant_type | authorization_code |
| form | code | 711ca5e1-7155-4b5c-b11b-bd2528b96ffe |
| form | redirect_uri | boldsmartlock%3A%2F%2Fauth |
| form | client_id | BoldAuthStaging |
| form | client_secret | cw3JrFa5vYQGGcm46pABAsPS |
| status | 200 | |
| header | Access-Control-Expose-Headers | authorization, content-type |
| header | Access-Control-Allow-Headers | authorization, content-type |
| header | Access-Control-Allow-Methods | GET, POST, DELETE, OPTIONS, PUT |
| header | Access-Control-Allow-Origin | * |
| header | Strict-Transport-Security | max-age=31536000; includeSubDomains |
| header | X-Frame-Options | SAMEORIGIN |
| header | X-Content-Type-Options | nosniff |
| header | X-XSS-Protection | 1; mode=block |
| header | Content-Security-Policy | default-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'none' |
| header | Referrer-Policy | no-referrer |
| header | Feature-Policy | self |
| header | Permissions-policy | interest-cohort=() |
{ "access_token": "f06a79f0-2ee4-4536-8ec5-c902f7f87238", "refresh_token": "babcee66-49b8-468f-b08a-2b1c3b1ba2b9", "token_type": "Bearer", "expires_in": 86400, "account_id": 1 } | ||
| header | Content-Type | application/x-www-form-urlencoded |
| form | token | f06a79f0-2ee4-4536-8ec5-c902f7f87238 |
| form | token_type_hint | access_token |
| status | 200 | |
| header | Access-Control-Expose-Headers | authorization, content-type |
| header | Access-Control-Allow-Headers | authorization, content-type |
| header | Access-Control-Allow-Methods | GET, POST, DELETE, OPTIONS, PUT |
| header | Access-Control-Allow-Origin | * |
| header | Strict-Transport-Security | max-age=31536000; includeSubDomains |
| header | X-Frame-Options | SAMEORIGIN |
| header | X-Content-Type-Options | nosniff |
| header | X-XSS-Protection | 1; mode=block |
| header | Content-Security-Policy | default-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'none' |
| header | Referrer-Policy | no-referrer |
| header | Feature-Policy | self |
| header | Permissions-policy | interest-cohort=() |
{} | ||
| header | Content-Type | application/x-www-form-urlencoded |
| form | token | a794fc8e-9f89-4965-b53e-49a0cb8506fb |
| form | token_type_hint | access_token |
| status | 200 | |
| header | Access-Control-Expose-Headers | authorization, content-type |
| header | Access-Control-Allow-Headers | authorization, content-type |
| header | Access-Control-Allow-Methods | GET, POST, DELETE, OPTIONS, PUT |
| header | Access-Control-Allow-Origin | * |
| header | Strict-Transport-Security | max-age=31536000; includeSubDomains |
| header | X-Frame-Options | SAMEORIGIN |
| header | X-Content-Type-Options | nosniff |
| header | X-XSS-Protection | 1; mode=block |
| header | Content-Security-Policy | default-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'none' |
| header | Referrer-Policy | no-referrer |
| header | Feature-Policy | self |
| header | Permissions-policy | interest-cohort=() |
{} | ||
| header | Content-Type | application/x-www-form-urlencoded |
| form | token | gR0Ul251IIy5utXI |
| form | token_type_hint | access_token |
| status | 200 | |
| header | Access-Control-Expose-Headers | authorization, content-type |
| header | Access-Control-Allow-Headers | authorization, content-type |
| header | Access-Control-Allow-Methods | GET, POST, DELETE, OPTIONS, PUT |
| header | Access-Control-Allow-Origin | * |
| header | Strict-Transport-Security | max-age=31536000; includeSubDomains |
| header | X-Frame-Options | SAMEORIGIN |
| header | X-Content-Type-Options | nosniff |
| header | X-XSS-Protection | 1; mode=block |
| header | Content-Security-Policy | default-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'none' |
| header | Referrer-Policy | no-referrer |
| header | Feature-Policy | self |
| header | Permissions-policy | interest-cohort=() |
{} | ||