Exchanges an access key and secret for a bearer token. Send the token as
Authorization: Bearer <token> on every other /api route.
The token is bound to the IP allowlist configured on the access key: a token
presented from an address outside ips is rejected as 401, not 403.
expiration is the token's lifetime in seconds, and allow_cash_out tells you
up front whether this key may call POST /api/payout.
The authentication endpoint receives a key and secret as input parameters and returns a bearer access token together with its expiration time, expressed in seconds.
Integrators should avoid calling this endpoint frequently. The recommended practice is to authenticate once, cache the token, and reuse it for subsequent requests. A new authentication should only be performed shortly before the token expires, minimizing unnecessary endpoint calls and ensuring optimal system performance.
How to use your bearer access token:
curl --request POST \
--url https://api.nxp.techworks.app/api/payin \
--header 'Authorization: Bearer <token>' \
--header 'accept: application/json' \
--header 'content-type: application/json'
