| form | grant_type | |
| form | client_id | |
| form | client_secret | |
| form | username | |
| form | password | |
| form | scope | |
| form | mfa_token | MFA token as obtained by the Verification API |
| header | Content-Type | application/x-www-form-urlencoded |
| form | grant_type | password |
| form | client_id | BoldAppStaging |
| form | client_secret | aivM9yDBV2cngb4XeV8tJmyd |
| form | username | %2B40711111298 |
| form | password | fin8%4053y38%214rj |
| form | scope | platform |
| form | mfa_token | b2edb2ec-f795-40e4-a10d-f9a3651dd91c |
| status | 400 | |
| header | Access-Control-Expose-Headers | authorization, content-type |
| header | Access-Control-Allow-Headers | authorization, content-type |
| header | Access-Control-Allow-Methods | GET, POST, DELETE, OPTIONS, PUT |
| header | Access-Control-Allow-Origin | * |
| header | Strict-Transport-Security | max-age=31536000; includeSubDomains |
| header | X-Frame-Options | SAMEORIGIN |
| header | X-Content-Type-Options | nosniff |
| header | X-XSS-Protection | 1; mode=block |
| header | Content-Security-Policy | default-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'none' |
| header | Referrer-Policy | no-referrer |
| header | Feature-Policy | self |
| header | Permissions-policy | interest-cohort=() |
{ "message": "This functionality is not supported. Please update the app to the latest version.", "code": "OldAppVersion", "errorMessage": "This functionality is not supported. Please update the app to the latest version.", "errorCode": "OldAppVersion" } | ||
| header | Content-Type | application/x-www-form-urlencoded |
| form | grant_type | authorization_code |
| form | code | 163182bf-4759-48ae-a11f-02d20289b944 |
| form | redirect_uri | https%3A%2F%2Fauthorization.sesamtechnology.com |
| form | client_id | BoldThirdPartyStaging |
| form | client_secret | nKgKVuwrbV59wMZH6XXgJ3Ja |
| status | 200 | |
| header | Access-Control-Expose-Headers | authorization, content-type |
| header | Access-Control-Allow-Headers | authorization, content-type |
| header | Access-Control-Allow-Methods | GET, POST, DELETE, OPTIONS, PUT |
| header | Access-Control-Allow-Origin | * |
| header | Strict-Transport-Security | max-age=31536000; includeSubDomains |
| header | X-Frame-Options | SAMEORIGIN |
| header | X-Content-Type-Options | nosniff |
| header | X-XSS-Protection | 1; mode=block |
| header | Content-Security-Policy | default-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'none' |
| header | Referrer-Policy | no-referrer |
| header | Feature-Policy | self |
| header | Permissions-policy | interest-cohort=() |
{ "access_token": "6392a1d9-59e2-473c-8f78-4977c5a61b07", "refresh_token": "993ec4c2-ebaa-44b6-a2a0-699938cdc831", "token_type": "Bearer", "expires_in": 86400, "account_id": 1 } | ||
{ "mfaToken": "9db28e66-aa10-45e2-9048-9e20aa1b5171", "password": "fin8@53y38!4rj", "clientId": "BoldAuthStaging", "clientSecret": "cw3JrFa5vYQGGcm46pABAsPS", "phoneNumber": "+40711111298" } |
| status | 200 | |
| header | Access-Control-Expose-Headers | authorization, content-type |
| header | Access-Control-Allow-Headers | authorization, content-type |
| header | Access-Control-Allow-Methods | GET, POST, DELETE, OPTIONS, PUT |
| header | Access-Control-Allow-Origin | * |
| header | Strict-Transport-Security | max-age=31536000; includeSubDomains |
| header | X-Frame-Options | SAMEORIGIN |
| header | X-Content-Type-Options | nosniff |
| header | X-XSS-Protection | 1; mode=block |
| header | Content-Security-Policy | default-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'none' |
| header | Referrer-Policy | no-referrer |
| header | Feature-Policy | self |
| header | Permissions-policy | interest-cohort=() |
{ "code": "147d56c6-b4cb-46ce-8f51-d2110f98025b", "expiration": "2026-08-21T15:13:22.036518894Z", "accountId": 1, "accountCreated": false, "registered": true, "emailAddress": "sesam@example.com" } | ||
| header | Content-Type | application/x-www-form-urlencoded |
| form | grant_type | authorization_code |
| form | code | 147d56c6-b4cb-46ce-8f51-d2110f98025b |
| form | redirect_uri | boldsmartlock%3A%2F%2Fauth |
| form | client_id | BoldAuthStaging |
| form | client_secret | cw3JrFa5vYQGGcm46pABAsPS |
| status | 200 | |
| header | Access-Control-Expose-Headers | authorization, content-type |
| header | Access-Control-Allow-Headers | authorization, content-type |
| header | Access-Control-Allow-Methods | GET, POST, DELETE, OPTIONS, PUT |
| header | Access-Control-Allow-Origin | * |
| header | Strict-Transport-Security | max-age=31536000; includeSubDomains |
| header | X-Frame-Options | SAMEORIGIN |
| header | X-Content-Type-Options | nosniff |
| header | X-XSS-Protection | 1; mode=block |
| header | Content-Security-Policy | default-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'none' |
| header | Referrer-Policy | no-referrer |
| header | Feature-Policy | self |
| header | Permissions-policy | interest-cohort=() |
{ "access_token": "bf192629-a5b8-45e5-9b04-6e340310d990", "refresh_token": "63b485dd-a1e2-4c6d-83a5-ff5eb3d356ff", "token_type": "Bearer", "expires_in": 86400, "account_id": 1 } | ||
| header | Content-Type | application/x-www-form-urlencoded |
| form | grant_type | refresh_token |
| form | client_id | BoldAuthStaging |
| form | client_secret | cw3JrFa5vYQGGcm46pABAsPS |
| form | refresh_token | 63b485dd-a1e2-4c6d-83a5-ff5eb3d356ff |
| status | 200 | |
| header | Access-Control-Expose-Headers | authorization, content-type |
| header | Access-Control-Allow-Headers | authorization, content-type |
| header | Access-Control-Allow-Methods | GET, POST, DELETE, OPTIONS, PUT |
| header | Access-Control-Allow-Origin | * |
| header | Strict-Transport-Security | max-age=31536000; includeSubDomains |
| header | X-Frame-Options | SAMEORIGIN |
| header | X-Content-Type-Options | nosniff |
| header | X-XSS-Protection | 1; mode=block |
| header | Content-Security-Policy | default-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'none' |
| header | Referrer-Policy | no-referrer |
| header | Feature-Policy | self |
| header | Permissions-policy | interest-cohort=() |
{ "access_token": "e28ff800-99d9-496f-9809-d3134ff6bf7f", "refresh_token": "d0e1c7cd-8840-424e-bf47-d3d1bcc33020", "token_type": "Bearer", "expires_in": 86400, "account_id": 1 } | ||
{ "mfaToken": "c09e042e-a457-4e4d-9802-bb5a3dbe3b2d", "password": "fin8@53y38!4rj", "clientId": "BoldAuthStaging", "clientSecret": "cw3JrFa5vYQGGcm46pABAsPS", "phoneNumber": "+40711111298" } |
| status | 200 | |
| header | Access-Control-Expose-Headers | authorization, content-type |
| header | Access-Control-Allow-Headers | authorization, content-type |
| header | Access-Control-Allow-Methods | GET, POST, DELETE, OPTIONS, PUT |
| header | Access-Control-Allow-Origin | * |
| header | Strict-Transport-Security | max-age=31536000; includeSubDomains |
| header | X-Frame-Options | SAMEORIGIN |
| header | X-Content-Type-Options | nosniff |
| header | X-XSS-Protection | 1; mode=block |
| header | Content-Security-Policy | default-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'none' |
| header | Referrer-Policy | no-referrer |
| header | Feature-Policy | self |
| header | Permissions-policy | interest-cohort=() |
{ "code": "f6bb4d45-fbdc-4852-bef9-cc8ce28a5311", "expiration": "2026-08-21T15:13:23.256116884Z", "accountId": 1, "accountCreated": false, "registered": true, "emailAddress": "sesam@example.com" } | ||
| header | Content-Type | application/x-www-form-urlencoded |
| form | grant_type | authorization_code |
| form | code | f6bb4d45-fbdc-4852-bef9-cc8ce28a5311 |
| form | redirect_uri | boldsmartlock%3A%2F%2Fauth |
| form | client_id | BoldAuthStaging |
| form | client_secret | cw3JrFa5vYQGGcm46pABAsPS |
| status | 200 | |
| header | Access-Control-Expose-Headers | authorization, content-type |
| header | Access-Control-Allow-Headers | authorization, content-type |
| header | Access-Control-Allow-Methods | GET, POST, DELETE, OPTIONS, PUT |
| header | Access-Control-Allow-Origin | * |
| header | Strict-Transport-Security | max-age=31536000; includeSubDomains |
| header | X-Frame-Options | SAMEORIGIN |
| header | X-Content-Type-Options | nosniff |
| header | X-XSS-Protection | 1; mode=block |
| header | Content-Security-Policy | default-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'none' |
| header | Referrer-Policy | no-referrer |
| header | Feature-Policy | self |
| header | Permissions-policy | interest-cohort=() |
{ "access_token": "740568c4-7d0a-41c5-a930-8db3a6207be6", "refresh_token": "f0154e17-6585-4e92-937c-ba7db4a165d6", "token_type": "Bearer", "expires_in": 86400, "account_id": 1 } | ||
| header | Content-Type | application/x-www-form-urlencoded |
| form | grant_type | authorization_code |
| form | code | f6bb4d45-fbdc-4852-bef9-cc8ce28a5311 |
| form | redirect_uri | boldsmartlock%3A%2F%2Fauth |
| form | client_id | BoldAuthStaging |
| form | client_secret | cw3JrFa5vYQGGcm46pABAsPS |
| status | 400 | |
| header | Access-Control-Expose-Headers | authorization, content-type |
| header | Access-Control-Allow-Headers | authorization, content-type |
| header | Access-Control-Allow-Methods | GET, POST, DELETE, OPTIONS, PUT |
| header | Access-Control-Allow-Origin | * |
| header | Strict-Transport-Security | max-age=31536000; includeSubDomains |
| header | X-Frame-Options | SAMEORIGIN |
| header | X-Content-Type-Options | nosniff |
| header | X-XSS-Protection | 1; mode=block |
| header | Content-Security-Policy | default-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'none' |
| header | Referrer-Policy | no-referrer |
| header | Feature-Policy | self |
| header | Permissions-policy | interest-cohort=() |
{ "error": "invalid_request", "error_description": "InvalidGrantCode", "message": "OAuth failure", "errorMessage": "OAuth failure" } | ||
{ "mfaToken": "5e137543-542d-4387-817c-03a2ca64cfcf", "password": "fin8@53y38!4rj", "clientId": "BoldAuthStaging", "clientSecret": "cw3JrFa5vYQGGcm46pABAsPS", "phoneNumber": "+40711111298" } |
| status | 200 | |
| header | Access-Control-Expose-Headers | authorization, content-type |
| header | Access-Control-Allow-Headers | authorization, content-type |
| header | Access-Control-Allow-Methods | GET, POST, DELETE, OPTIONS, PUT |
| header | Access-Control-Allow-Origin | * |
| header | Strict-Transport-Security | max-age=31536000; includeSubDomains |
| header | X-Frame-Options | SAMEORIGIN |
| header | X-Content-Type-Options | nosniff |
| header | X-XSS-Protection | 1; mode=block |
| header | Content-Security-Policy | default-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'none' |
| header | Referrer-Policy | no-referrer |
| header | Feature-Policy | self |
| header | Permissions-policy | interest-cohort=() |
{ "code": "682f2227-c5d8-447c-b572-5b389d1dbf8e", "expiration": "2026-08-21T15:13:24.61429154Z", "accountId": 1, "accountCreated": false, "registered": true, "emailAddress": "sesam@example.com" } | ||
| header | Content-Type | application/x-www-form-urlencoded |
| form | grant_type | authorization_code |
| form | code | 682f2227-c5d8-447c-b572-5b389d1dbf8e |
| form | redirect_uri | boldsmartlock%3A%2F%2Fauth |
| form | client_id | BoldAuthStaging |
| form | client_secret | cw3JrFa5vYQGGcm46pABAsPS |
| status | 200 | |
| header | Access-Control-Expose-Headers | authorization, content-type |
| header | Access-Control-Allow-Headers | authorization, content-type |
| header | Access-Control-Allow-Methods | GET, POST, DELETE, OPTIONS, PUT |
| header | Access-Control-Allow-Origin | * |
| header | Strict-Transport-Security | max-age=31536000; includeSubDomains |
| header | X-Frame-Options | SAMEORIGIN |
| header | X-Content-Type-Options | nosniff |
| header | X-XSS-Protection | 1; mode=block |
| header | Content-Security-Policy | default-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'none' |
| header | Referrer-Policy | no-referrer |
| header | Feature-Policy | self |
| header | Permissions-policy | interest-cohort=() |
{ "access_token": "b7622147-3d90-4365-9520-cb85d76205df", "refresh_token": "d963201d-8241-49e4-b22d-5944beb809d1", "token_type": "Bearer", "expires_in": 86400, "account_id": 1 } | ||
| header | Authorization | Bearer b7622147-3d90-4365-9520-cb85d76205df |
| status | 200 | |
| header | Access-Control-Expose-Headers | authorization, content-type |
| header | Access-Control-Allow-Headers | authorization, content-type |
| header | Access-Control-Allow-Methods | GET, POST, DELETE, OPTIONS, PUT |
| header | Access-Control-Allow-Origin | * |
| header | Strict-Transport-Security | max-age=31536000; includeSubDomains |
| header | X-Frame-Options | SAMEORIGIN |
| header | X-Content-Type-Options | nosniff |
| header | X-XSS-Protection | 1; mode=block |
| header | Content-Security-Policy | default-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'none' |
| header | Referrer-Policy | no-referrer |
| header | Feature-Policy | self |
| header | Permissions-policy | interest-cohort=() |
[{ "id": 1, "email": "sesam@example.com", "phone": "+40711111298", "phoneCountryCode": "RO", "isSystemAccount": false, "isSupportAccount": false, "isSystemIntegration": false, "dateCreated": "2026-08-21T15:03:24.587596Z", "dateModified": "2026-08-21T15:03:24.673962Z", "dateLastAuthentication": "2026-08-21T15:03:24.648392Z", "registered": true }] | ||
| header | X-Auth-Token | b7622147-3d90-4365-9520-cb85d76205df |
| status | 401 | |
| header | Access-Control-Expose-Headers | authorization, content-type |
| header | Access-Control-Allow-Headers | authorization, content-type |
| header | Access-Control-Allow-Methods | GET, POST, DELETE, OPTIONS, PUT |
| header | Access-Control-Allow-Origin | * |
| header | Strict-Transport-Security | max-age=31536000; includeSubDomains |
| header | X-Frame-Options | SAMEORIGIN |
| header | X-Content-Type-Options | nosniff |
| header | X-XSS-Protection | 1; mode=block |
| header | Content-Security-Policy | default-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'none' |
| header | Referrer-Policy | no-referrer |
| header | Feature-Policy | self |
| header | Permissions-policy | interest-cohort=() |
{ "message": "Authentication is possible but has failed or not yet been provided.", "errorMessage": "Authentication is possible but has failed or not yet been provided." } | ||