Skip to main content

Authenticate API

Process

  • MERCHANT calls this API to obtain a JWT Token.

  • Baokim authenticates against the Merchant integrating directly with Baokim, i.e.:

  • If a Master integrates, authentication uses the Master's information.

  • If a Sub integrates, authentication uses the Sub's information.

API Information

URL: /b2b/auth-service/api/oauth/get-token

Method: POST

Request

Main Parameters Table

No.Field NameData TypeRequiredDescription
1merchant_codeString(50)Merchant code provided by Baokim
2client_idString(50)Merchant's Client ID provided by Baokim
3client_secretString(50)Merchant's Client Secret provided by Baokim

Request Example

{
"merchant_code": "BAOKIMMRC",
"client_id": "BAOKIMMRC",
"client_secret": "iOiJKV1QiLCJhbGciOiJIUzI1NiJ9"
}

Response

Main Parameters Table

No.Field NameData TypeRequiredDescription
1codeNumber(3)Baokim error code
2messageString(200)Baokim error code message
3dataObjectData returned by Baokim

data Information

No.Field NameData TypeRequiredDescription
1access_tokenStringJWT Token string
2token_typeStringToken type
3expires_atDateTimeToken expiration time

Response Example

{
"code": 100,
"message": "Successfully",
"data": {
"access_token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJodHRwOi8vbG9jYWxob3N0OjkyOTIvYXBpL2IyYl9hdXRoL2xvZ2luIiwiaWF0IjoxNzA2MDgwODU1LCJleHAiOjE3MDYwODQ0NTUsIm5iZiI6MTcwNjA4MDg1NSwianRpIjoiV0FUWnpJZTB3d0NuU1dpNSIsInN1YiI6IjEiLCJwcnYiOiIyM2JkNWM4OTQ5ZjYwMGFkYjM5ZTcwMWM0MDA4NzJkYjdhNTk3NmY3IiwibWVyY2hhbnRfaW5mbyI6eyJjb2RlIjoiYWJjIn0sInNjb3BlcyI6W3siYWN0aW9uIjoiR0VUIiwidXJpIjoiYWJjLmNvbSJ9LHsiYWN0aW9uIjoiUE9TVCIsInVyaSI6Inh5ei5jb20ifV19.aRfdvwFz8CDiBqHoCG8IGfPC0bO4vhXRvY76dupRx9k",
"token_type": "bearer",
"expires_at": "2025-10-30 14:41:00"
}
}

Error Codes

Error CodeDescription
100Success
11Failed
401Merchant verify failed
422Validation error