Skip to main content
POST
Exchange credentials for a JWT
Only the payout endpoints require a JWT. Payin endpoints are authenticated by your API key, request signature and IP allowlist alone — a payin-only integration never calls this endpoint.
The fields above are what you encrypt, not what goes on the wire. The body is always { "data": "<aes-256-gcm ciphertext>" } — see Authentication.

Example request

The snippets below assume you’ve already encrypted the body and computed the signature — see the Quickstart for the full helper in Node and Python.

Using the token

Pass access_token as Authorization: Bearer <token> on every payout and beneficiary request. It expires in 900 seconds and is bound to both your account and the mode implied by the host — a sandbox token will not work against live. A 401 here usually means the email, password and API key do not all belong to the same user account. See Errors for the full envelope shape and code list.

Authorizations

x-api-key
string
header
required

Identifies your account. Issued from Developer Tools in the dashboard.

Headers

x-timestamp
integer<int64>
required

Unix epoch in seconds — not milliseconds. Must be within ±5 minutes of our clock, which is what makes a captured request unusable later. Keep your client's clock NTP-synced.

Example:

1748023400

x-signature
string
required

HMAC-SHA256 over the signing string, hex encoded. The timestamp is part of what is signed, so a replayed body cannot be re-dated. See https://docs.pontisglobe.com/authentication for how it is built.

Example:

"2f8a9b4c1d7e0a3f6b8c2d5e9f1a4b7c0d3e6f9a2b5c8d1e4f7a0b3c6d9e2f5a"

Body

application/json
email
string<email>
required

Must belong to the same user account as the API key.

password
string
required

Response

Token issued.

ok
enum<boolean>
Available options:
true
data
object