# About Authorization

## Get Authorization Token API  

The **Get Authorization Token API** is a critical step for authenticating all subsequent API requests. This token ensures secure communication by verifying the legitimacy of the requesting source.  

### <span style="color:#0a58ca">Purpose</span>  
The API generates an **authentication token** that must be included in the headers of all subsequent API requests. This token acts as proof of authorization and helps maintain secure interactions with Enkash servers.  

#### **Endpoint**:  

| **Environment** | **Endpoint URL**                                |  
|------------------|------------------------------------------------|  
| **Test**         | `https://ekpayout-uat.enkash.in/oauth/token` |  

- **Method:** `POST`  

#### **Request Headers**:  

Include the following headers in your API request  

| **Header**       | **Value**                     | **Description**                                      |  
|-------------------|-------------------------------|----------------------------------------------------|  
| `Content-Type`    | `application/json`           | Specifies the media type of the request body.      |  
| `API-Key`         | Your unique API key          | Provided by Enkash upon registration.              |  

#### **Sample Request**:  

```json  
curl --location 'https://ekpayout-uat.enkash.in/oauth/token' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--header 'Authorization: Basic ZW5rYXNoLWNsaWVudDplbmthc2gtc2VjcmV0' \
--header 'Cookie: _cfuvid=yGxHvg3YoXDw5.TqhyNajXB5rfz3FgUUHcHaZl3G_i0-1740119862393-0.0.1.1-604800000' \
--data-urlencode 'username=enkash@enkash.com' \
--data-urlencode 'grant_type=password' \
--data-urlencode 'password=Test@1234' 
```  

#### **Response**:  

Upon a successful request, the server will return a JSON object containing the generated token and additional details:  

| **Field**        | **Type**         | **Description**                                                    |  
|-------------------|------------------|--------------------------------------------------------------------|  
| `token`          | `string`         | The generated authentication token                               |  
| `expiry`         | `integer (int64)`| Token expiration time in milliseconds                            |  
| `resultCode`     | `integer (int32)`| Status code indicating the outcome of the token generation request |  
| `resultMessage`  | `string`         | Additional information about the request's result                |  


#### **Sample Response**:  

```json  
{  
  "token": "abcdef1234567890",  
  "expiry": 1672531199000,  
  "resultCode": 200,  
  "resultMessage": "Token generated successfully."  
}  
```  

### <span style="color:#0a58ca">Integration Notes</span>   

- The token must be included in the `Authorization` header for all subsequent API requests:  
  ```  
  Authorization: Bearer {token}  
  ```  
- Ensure that you handle token expiration by refreshing the token before its expiry time. 

#### **Related Pages**:
[Get Authorization Token](https://docs.enkash.com/api-7742755.md)

