generated: '2026-07-19' method: searched source: https://docs.fiatrepublic.com/docs/authentication docs: https://docs.fiatrepublic.com/docs/authentication summary: types: [oauth2] oauth2_flows: [clientCredentials] token_transport: bearer request_signing: none schemes: - name: OAuth2ClientCredentials type: oauth2 flow: clientCredentials token_url_sandbox: https://sandbox.fiatrepublic.com/passport/oauth/token grant_type: client_credentials credentials: URL-encoded form data (client_id, client_secret, grant_type, scope) scopes: - PAYMENTS - OXYGEN access_token_format: JWT (bearer) access_token_ttl_seconds: 3599 applied_via: Authorization Bearer header on all protected endpoints sources: [https://docs.fiatrepublic.com/docs/authentication] notes: >- OAuth 2.0 client-credentials flow. Client id/secret are generated in the Developers section of the Dashboard; the secret is shown once and cannot be retrieved afterward. A separate PAYMENTS vs OXYGEN scope selects which product surface the access token can reach (PAYMENTS expands to "PAYMENTS payments.*"). No HMAC/request signing on API calls; webhooks are separately signed with HMAC-SHA256 (see conventions/ and asyncapi/).