generated: '2026-09-14' method: searched source: https://apiportal.eastwestbank.com/AuthorizationAPI docs: https://apiportal.eastwestbank.com/AuthorizationAPI note: >- East West Bancorp publishes no API of its own; the group's API surface is the Bridge Open Banking program operated by its banking subsidiary, East West Bank, at apiportal.eastwestbank.com. No OpenAPI or Swagger document is publicly downloadable — the API list, product library and reference render only after portal sign-in — so this profile is transcribed from the two pages the provider serves anonymously: the Authorization API page (which carries the full token exchange, including the literal token endpoint) and the portal FAQ. Nothing here is derived from a securityScheme, because there is no public spec. summary: types: - oauth2 oauth2_flows: - clientCredentials api_key_in: [] bearer: true schemes: - name: OAuth2 client credentials (Authorization API) type: oauth2 scheme: OAuth 2.0 Authorization Framework, two-legged / machine-to-machine sources: - https://apiportal.eastwestbank.com/AuthorizationAPI - https://apiportal.eastwestbank.com/faqs flows: - flow: clientCredentials token_url: https://ewbpoc.okta.com/oauth2/ausdaetdg9zY8EZuI2p6/v1/token token_url_status: >- Published verbatim by the provider. Probed 2026-09-14: the Okta authorization-server metadata for this server id returns 404 (Okta "Page Not Found"), and the org slug "ewbpoc" reads as a proof-of-concept tenant, so the documented endpoint may be stale. Recorded as the provider states it; not corrected, not guessed. grant_type: client_credentials request_content_type: application/x-www-form-urlencoded parameters: - client_id - client_secret - grant_type response_fields: - access_token - token_type - expires_in token_type: Bearer expires_in_seconds: 86400 note: >- Identity provider is Okta. The Authorization API page shows the token call with client_id and client_secret in the form body; the portal FAQ additionally documents base-64 encoding the ClientID and ClientSecret and prefixing "Basic " on the token call, so both credential presentations appear in the provider's own documentation. credentials: client_id: issued per application created in the developer portal client_secret: issued per application created in the developer portal encoding: >- Base-64 encode ClientID and ClientSecret; the FAQ recommends encoding in application logic rather than storing a static encoded string, and requires the "Basic" prefix on the token call. application_model: >- An "application" is a collection of one or more API resources reachable with a single authentication credential. A developer must create one before calling the sandbox. request_authorization: header: Authorization format: 'Bearer ' applies_to: every protected API endpoint transport_security: client_certificate_required: true scope: >- A client certificate is required for connectivity to the sandbox and production environments; no certificate is needed to browse the Bridge Open Banking portal. Certificates and access credentials are issued by East West Bank GTS during onboarding. source: https://apiportal.eastwestbank.com/faqs troubleshooting: - status: 401 title: Unauthorized causes: - client-id and secret not correctly matched against the application that was created - base-64 encoding not formatted per the authorization documentation - '"Basic" not prefixed to the encoded ClientID and ClientSecret on the token call' - access token invalidated or expired source: https://apiportal.eastwestbank.com/faqs