# 获取访问令牌 (/zh/docs/conta-digital/endpoints/authentication/post_oauth_token)

## POST /oauth/token

`POST https://api.hub.payzu.com.br/api/v1/oauth/token`

Exchanges the credential for an access token valid for 15 minutes. Send `client_id` and `client_secret` in the `Authorization: Basic` header or in the body, as `application/x-www-form-urlencoded` or JSON. Exchanges are limited per `client_id` and IP, and the credential IP allowlist applies here too.

### Body params

| Field | Type | Required | Details |
| --- | --- | --- | --- |
| `grant_type` | string | yes | Always `client_credentials`. — `client_credentials` |
| `client_id` | string | no | Credential `client_id`, when it does not go in the `Authorization: Basic` header. |
| `client_secret` | string | no | Credential `client_secret`, when it does not go in the `Authorization: Basic` header. |

### Responses

**200** Token issued.

| Field | Type | Required | Details |
| --- | --- | --- | --- |
| `access_token` | string | yes | Access token. Goes in the `Authorization: Bearer` header of the other routes. |
| `token_type` | string | yes | Always `Bearer`. — `Bearer` |
| `expires_in` | integer | yes | Token lifetime, in seconds. |
| `scope` | string | yes | Credential scopes, separated by spaces. |

**400** Invalid request.

| Field | Type | Required | Details |
| --- | --- | --- | --- |
| `message` | string | yes | Description in Portuguese, ready to display. It may change at any time. |
| `code` | string | yes | Stable error code. Your system decides what to do based on it. |
| `details` | object | no | Structured error context, when available. |

**401** Missing, invalid or expired credential.

| Field | Type | Required | Details |
| --- | --- | --- | --- |
| `message` | string | yes | Description in Portuguese, ready to display. It may change at any time. |
| `code` | string | yes | Stable error code. Your system decides what to do based on it. |
| `details` | object | no | Structured error context, when available. |

**403** Not allowed: scope, IP or disabled operation.

| Field | Type | Required | Details |
| --- | --- | --- | --- |
| `message` | string | yes | Description in Portuguese, ready to display. It may change at any time. |
| `code` | string | yes | Stable error code. Your system decides what to do based on it. |
| `details` | object | no | Structured error context, when available. |

**429** Request limit exceeded.

| Field | Type | Required | Details |
| --- | --- | --- | --- |
| `message` | string | yes | Description in Portuguese, ready to display. It may change at any time. |
| `code` | string | yes | Stable error code. Your system decides what to do based on it. |
| `details` | object | no | Structured error context, when available. |