generated: '2026-10-09' method: searched source: https://docs.monite.com/api/concepts/authentication docs: https://docs.monite.com/api/concepts/authentication summary: types: - http - oauth2-style token endpoint description: All requests use a Bearer token generated by Monite from a Client ID and Client Secret created in the Monite Partner Portal. Tokens come from POST /auth/token (no auth headers required) and can be revoked with POST /auth/revoke. HTTPS only. schemes: - name: HTTPBearer type: http scheme: bearer sources: - openapi/monite-openapi.yml - https://docs.monite.com/api/concepts/authentication token_endpoint: url: https://api.monite.com/v1/auth/token sandbox_url: https://api.sandbox.monite.com/v1/auth/token operation: post_auth_token revoke_operation: post_auth_revoke grant_types: - name: client_credentials description: Standard OAuth 2.0 grant for backend-to-backend communication; yields a partner-level token with the highest privileges (required for /entities and partner /settings operations). - name: entity_user description: Custom Monite grant type; requires entity_user_id and yields an entity-user token whose permissions come from the user's role (RBAC). token_lifetime: expires_in is returned in seconds (example value 1800); docs describe tokens as short-lived with an adjustable lifespan. authorization_model: type: RBAC description: Entity-user tokens are checked against role permissions (not_allowed, allowed, allowed_for_own) per object_type and action. See scopes/monite-scopes.yml. required_headers: - name: x-monite-version description: API version, required on every request. - name: x-monite-entity-id description: Entity that owns the resource; required to access entity-owned resources. credentials_source: https://docs.monite.com/get-started/credentials