Tokens

Gets the details of a merchant API token.

<b>Authorization</b>: End user token is required.

<b>User permissions required</b>: CanViewTokens

get/api/v1/tokens/{id}

Request

  • Base URL: https://api.nofrixion.com
  • URL: https://api.nofrixion.com/api/v1/tokens/{id}
  • Auth: API key in header Authorization

Path parameters

idstring uuid required

The ID of the merchant token.

Response

Returns the merchant API token details.

idstring uuid
merchantIDstring uuid
descriptionstring nullable
permissionTypesstring[] nullable

The permissions that the merchant token supports.

insertedstring date-time
lastUpdatedstring date-time
tokenstring nullable

The JWT merchant token. It will only be available when the merchant token is initially created. The token is not stored by NoFrixion.

isEnabledboolean

If set to false the merchant token will not be accepted to authorise a request.

sharedSecretAlgorithm'None' | 'HMAC_SHA1' | 'HMAC_SHA256' | 'HMAC_SHA384' | 'HMAC_SHA512'

Optional shared secret algorithm to use for HMAC authentication.

sharedSecretBase64string nullable

The base 64 encoded shared secret that is used for request authentication with an HMAC. Note this property will ONLY be set when the token is initially created. It is not possible to retrieve the secret afterwards. If it is lost a new token should be created.

requestSignatureVersioninteger

Represent the version of the overall merchant token. This field is to allow the secret and public key mechanisms to vary over time. For example if the HTTP header fields to include in the algorithms change this version will faciliatate keeping track of which signature versions a particular merchant token is using.

expiresAtstring date-time nullable

Optional. If set indicates the merchant token is not valid after the specified expiry date.

canAuthoriseboolean

True if the merchant token can be authorised by the user who loaded it.

hasCurrentUserAuthorisedboolean

True if the beneficiary was loaded for a user and that user has already authorised the latest version of the beneficiary.

authorisersRequiredCountinteger

The number of authorisers required for this merchant token. Is determined by business settings on the source account and/or merchant.

authorisersCompletedCountinteger

The number of distinct authorisers that have authorised the merchant token.

authenticationMethodsstring[] nullable

A list of authentication types allowed to authorise the merchant token.

lastAuthorisedstring date-time nullable
ipAddressWhiteliststring nullable

Optional. If set represents a comma separated list of IP addresses that this token is authorised to be used from. Attempts to use the token from an IP address not in the list will be rejected.

isArchivedboolean

Indicates whether the merchant token is archived.

noncestring nullable required

Changes

No recorded changes to this endpoint across all 2 revisions of this API.