generated: '2026-09-19' method: searched source: openapi/airalo-partner-api-openapi.yml docs: - https://developers.partners.airalo.com/request-access-token-11883021e0 - https://developers.partners.airalo.com/ip-allowlist-whitelisting-2327548m0 summary: types: - http schemes: - name: bearerAuth type: http scheme: bearer bearerFormat: JWT description: Access token from POST /v2/token (OAuth2 client_credentials grant with client_id + client_secret). Tokens are valid for 24 hours; the token endpoint is limited to 3 requests per minute. sources: - openapi/airalo-partner-api-openapi.yml token_endpoint: operation_id: requestAccessToken path: POST /v2/token grant_type: client_credentials content_type: application/x-www-form-urlencoded parameters: [client_id, client_secret, grant_type] response: {token_type, expires_in, access_token} lifetime_hours: 24 rate_limit: 3 requests per minute scopes_published: false docs: https://developers.partners.airalo.com/request-access-token-11883021e0 note: >- An RFC 6749 client-credentials exchange that mints a bearer token, but Airalo declares no oauth2 securityScheme in its published fragments and documents no scopes — authorization is all-or-nothing per credential pair. No scopes/ artifact is emitted for that reason. credential_issuance: location: Partner Platform (https://app.partners.airalo.com) self_serve: false note: Credentials are issued after an account manager onboards the company; the same pair works in Sandbox and Production. network_controls: ip_allowlist: supported: true default_state: off scope: per company, covers Sandbox and Production formats: [IPv4, IPv6, IPv4 CIDR, IPv6 CIDR] max_entries: 100 rejection: HTTP 403, body code 89 effective: immediately on save docs: https://developers.partners.airalo.com/ip-allowlist-whitelisting-2327548m0 console_sso: protocol: SAML 2.0 applies_to: Partner Platform console, not the API idps: [Okta, OneLogin, Google Workspace, Microsoft Azure] roles: [Admin, Operations, Finance, Employee] domain_verification: TXT record within 72 hours docs: https://developers.partners.airalo.com/faq-752238m0 webhook_authentication: direction: inbound-to-partner header: airalo-signature algorithm: HMAC-SHA512 key: partner API secret docs: https://developers.partners.airalo.com/webhook-definition-1380483m0