Creates a new merchant API token.
<b>Authorization</b>: End user token is required.
<b>User permissions required</b>: CanCreateTokens
Request
- Base URL: https://api.nofrixion.com
- URL: https://api.nofrixion.com/api/v1/tokens
- Auth: API key in header Authorization
Request body
The merchant id to add to the token
Token description
Optional shared secret algorithm to use for HMAC authentication. If set a shared secret will be returned when the token is intially created but not on any subsequent retrievals.
The list of permissions tho grant to the merchant token.
Optional. If set represents a comma separated list of IP addresses that this token is authorised to be used from. Attempts to use the token from an IP address not in the list will be rejected.
Response
OK
The permissions that the merchant token supports.
The JWT merchant token. It will only be available when the merchant token is initially created. The token is not stored by NoFrixion.
If set to false the merchant token will not be accepted to authorise a request.
Optional shared secret algorithm to use for HMAC authentication.
The base 64 encoded shared secret that is used for request authentication with an HMAC. Note this property will ONLY be set when the token is initially created. It is not possible to retrieve the secret afterwards. If it is lost a new token should be created.
Represent the version of the overall merchant token. This field is to allow the secret and public key mechanisms to vary over time. For example if the HTTP header fields to include in the algorithms change this version will faciliatate keeping track of which signature versions a particular merchant token is using.
Optional. If set indicates the merchant token is not valid after the specified expiry date.
True if the merchant token can be authorised by the user who loaded it.
True if the beneficiary was loaded for a user and that user has already authorised the latest version of the beneficiary.
The number of authorisers required for this merchant token. Is determined by business settings on the source account and/or merchant.
The number of distinct authorisers that have authorised the merchant token.
A list of authentication types allowed to authorise the merchant token.
Optional. If set represents a comma separated list of IP addresses that this token is authorised to be used from. Attempts to use the token from an IP address not in the list will be rejected.
Indicates whether the merchant token is archived.
Changes
No recorded changes to this endpoint across all 2 revisions of this API.