Skip to main content
POST
Obtain JWT access token

Overview

The partner authentication endpoint allows trusted third-party partners to exchange their issued API credentials for a JWT (JSON Web Token) that can be used to authenticate subsequent API requests on behalf of their clients.

Request

Headers

  • Content-Type: application/json

Body Parameters

string
required
Your unique API key issued by Targeter for your approved partnership
string
required
Your plain-text API secret issued by Targeter. Send the secret exactly as provided — not a bcrypt hash or other encoded form.

Example Request

Use snake_case field names (api_key, api_secret). CamelCase names such as apiKey return 400.

Response

Success Response (200)

string
JWT token to be used in Authorization header for subsequent requests
string
Token type (always “Bearer”)
integer
Token validity in seconds (3600 = 1 hour)

Example Response

Error Responses

400 - Invalid request payload

401 - Invalid API credentials

500 - Internal server error

Usage Notes

  • Token Expiration: JWT tokens expire after 1 hour for security
  • Refresh: You must obtain a new token when the current one expires
  • Security: Never expose your issued API secret in client-side code — these are for server-to-server communication only
  • Storage: Store tokens securely and refresh them before expiration
  • Credentials: Only use API credentials issued specifically to your approved partnership
  • Base URL: Your API base URL is provided with your credentials (e.g. https://app.targeter.tech/api)

Next Steps

Once you have your JWT token, you can use it to make authenticated requests on behalf of your clients:

Body

application/json
api_key
string
required

API key issued for your partnership

Example:

"YOUR_ISSUED_PARTNER_KEY"

api_secret
string
required

Plain-text API secret issued for your partnership (not a bcrypt hash)

Example:

"YOUR_ISSUED_PARTNER_SECRET"

Response

Successfully authenticated

access_token
string
required

JWT for the Authorization header

Example:

"eyJhbGciOiJIUzI1NiIsInR5cCI6..."

token_type
string
required
Example:

"Bearer"

expires_in
integer
required

Token lifetime in seconds

Example:

3600