openapi: 3.0.3 info: title: Paymob Accept Legacy (v2) Accounts Authentication API version: '2.0' description: 'The legacy Paymob Accept API uses a three-step flow: authenticate to receive a bearer auth_token, register an order, then request a payment_key. The payment_key is used either with the iframe redirect or the headless /payments/pay endpoint. Refund, void, capture, transaction inquiry, and saved-card MOTO operations are exposed on this surface.' contact: name: Paymob Developers url: https://developers.paymob.com servers: - url: https://accept.paymob.com description: Egypt production - url: https://ksa.paymob.com description: Saudi Arabia production - url: https://uae.paymob.com description: UAE production - url: https://oman.paymob.com description: Oman production - url: https://pakistan.paymob.com description: Pakistan production security: - BearerAuth: [] tags: - name: Authentication paths: /api/auth/tokens: post: summary: Authenticate Merchant operationId: createAuthToken tags: - Authentication description: Exchange the merchant API key for a short-lived auth_token (60 minutes). security: [] requestBody: required: true content: application/json: schema: type: object required: - api_key properties: api_key: type: string responses: '201': description: Token created content: application/json: schema: type: object properties: token: type: string profile: type: object additionalProperties: true /api/auth/token/: post: summary: Generate Access Token operationId: generatePayoutsToken tags: - Authentication description: Generate an OAuth2 access token. Token must be refreshed every 60 minutes. security: [] requestBody: required: true content: application/x-www-form-urlencoded: schema: type: object required: - username - password - grant_type - client_id - client_secret properties: grant_type: type: string enum: - password username: type: string password: type: string client_id: type: string client_secret: type: string responses: '200': description: Token issued content: application/json: schema: $ref: '#/components/schemas/Token' /api/auth/token/refresh/: post: summary: Refresh Access Token operationId: refreshPayoutsToken tags: - Authentication security: [] requestBody: required: true content: application/x-www-form-urlencoded: schema: type: object required: - refresh_token - grant_type - client_id - client_secret properties: grant_type: type: string enum: - refresh_token refresh_token: type: string client_id: type: string client_secret: type: string responses: '200': description: Token refreshed content: application/json: schema: $ref: '#/components/schemas/Token' components: schemas: Token: type: object properties: access_token: type: string refresh_token: type: string expires_in: type: integer token_type: type: string scope: type: string securitySchemes: BearerAuth: type: http scheme: bearer description: Bearer auth_token from /api/auth/tokens (60-minute TTL).