OAuth 2.0 with the client_credentials grant. No browser, no redirects.
Required headers
| Header | Where | Description |
|---|---|---|
Authorization | everywhere | Bearer <access_token> from /sapi/auth/token. |
X-Peppol-Participant-Id | /sapi/document/* | Your identifier as {scheme}:{id}, e.g. 0245:2020317068 — under scheme 0245 the identifier is the ten-digit Slovak DIČ. It must belong to the same organisation as the token. |
Idempotency-Key | /sapi/document/send | A UUID you generate. Valid for 24 hours. |
Token lifecycle
- Access token
- 15 min
- Refresh token
- 7 days
- Refresh signal
- 3 min before expiry
- Account lockout
- 15 min
Cache the token and refresh it only near expiry. /sapi/auth/token/status
tells you when — the should_refresh flag flips on three minutes before it
expires. A renewal also rotates the refresh token, so always store the new
one.