Session and tokens
Create a session and get an access token
Send the client id and client secret from your ABDM sandbox registration. The response carries a bearer token that every module API accepts in the Authorization header.
This is the one call that does not itself need a bearer token, which is why security is empty here.
The token is short lived. Read A fresh UUID that you generate for this request. It is how you and the gateway correlate a call with its callback and with a support ticket, so log it. Reusing one across requests makes both impossible. The current time in ISO 8601 UTC, with milliseconds and the Which consent manager you are talking to. The client id issued when you registered on the ABDM sandbox. The client secret issued alongside the client id. It is a credential. Keep it server side, never in a mobile or browser build. The only accepted value is A session was created and a bearer token was issued.expiresIn from the response rather than assuming a duration, and refresh before it runs out instead of waiting for a 401.Headers
REQUEST-IDstringRequiredTIMESTAMPstringRequiredZ suffix. The gateway rejects a request whose timestamp has drifted too far from its own clock, so take this from a synchronised clock rather than from a local one.X-CM-IDstringRequiredsbx on the sandbox and abdm in production. Sending the wrong one against the right host is a common first-day failure and reads as an authorisation error.Body
clientIdstringRequiredclientSecretstringRequiredgrantTypestringRequiredclient_credentials.Responses
200