# Authentication

URL: https://postman.slovakodata.com/developers/en/autentifikacia/
Updated: 2026-07-24

OAuth 2.0 with the client_credentials grant, required headers and the token lifecycle.

OAuth 2.0 with the `client_credentials` grant. No browser, no redirects.

### Required headers

| Header | Where | Description |
|---|---|---|
| `Authorization` | everywhere | `Bearer <access_token>` from `/sapi/auth/token`. |
| `X-Peppol-Participant-Id` | `/sapi/document/*` | Your identifier as `{scheme}:{id}`, e.g. `0245:2020317068` — under scheme `0245` the identifier is the ten-digit Slovak DIČ. It must belong to the same organisation as the token. |
| `Idempotency-Key` | `/sapi/document/send` | A UUID you generate. Valid for 24 hours. |

### Token lifecycle

<dl class="facts">
  <div class="fact">
    <dt>Access token</dt>
    <dd>15<small> min</small></dd>
  </div>
  <div class="fact">
    <dt>Refresh token</dt>
    <dd>7<small> days</small></dd>
  </div>
  <div class="fact">
    <dt>Refresh signal</dt>
    <dd>3<small> min before expiry</small></dd>
  </div>
  <div class="fact">
    <dt>Account lockout</dt>
    <dd>15<small> min</small></dd>
  </div>
</dl>

**Cache** the token and refresh it only near expiry. `/sapi/auth/token/status`
tells you when — the `should_refresh` flag flips on three minutes before it
expires. A renewal also rotates the refresh token, so always store the new
one.

**Do not fetch a token per request.** Repeated failed token requests
temporarily lock the account — you get `423` with code `SAPI-AUTH-005`. It is
brute-force protection.
