> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kirafin.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Get access token

> Use your `client_id` and `password` to get an access token.

This call needs only the `x-api-key` header. It is the one endpoint that does **not** need a bearer token.

The token arrives in `data.access_token`. Send it as `Authorization: Bearer <access_token>` on every other call, together with `x-api-key`.

`data.expires_in` is the token's life in seconds. There is no refresh token: when the token expires, or when a call answers `401`, call this endpoint again.

Save the token and reuse it until it is close to expiry. Do not log in before every request.

See the [Authentication](/get-started/authentication) guide for more detail.



## OpenAPI

````yaml /openapi/kira-api.2026-04-14.json post /auth
openapi: 3.1.0
info:
  title: Kira API
  version: '2026-04-14'
  description: >-
    REST API for users, KYC/KYB verification, virtual accounts, payouts,
    recipients, and webhooks. Every request requires an `x-api-key` header and a
    bearer access token (see Authentication). Pin your account to version
    `2026-04-14` before integrating.
  contact:
    name: Kira API Support
    email: support@kirafin.ai
servers:
  - url: https://api.balampay.com
    description: Production
  - url: https://api.balampay.com/sandbox
    description: Sandbox
security:
  - bearerAuth: []
    apiKeyAuth: []
tags:
  - name: Authentication
  - name: Versioning
  - name: Users
  - name: Virtual Accounts
  - name: Recipients
  - name: Quotations
  - name: Payouts
  - name: Reference
paths:
  /auth:
    post:
      tags:
        - Authentication
      summary: Get access token
      description: >-
        Use your `client_id` and `password` to get an access token.


        This call needs only the `x-api-key` header. It is the one endpoint that
        does **not** need a bearer token.


        The token arrives in `data.access_token`. Send it as `Authorization:
        Bearer <access_token>` on every other call, together with `x-api-key`.


        `data.expires_in` is the token's life in seconds. There is no refresh
        token: when the token expires, or when a call answers `401`, call this
        endpoint again.


        Save the token and reuse it until it is close to expiry. Do not log in
        before every request.


        See the [Authentication](/get-started/authentication) guide for more
        detail.
      operationId: post_auth
      parameters:
        - in: header
          name: X-Api-Version
          required: false
          description: >-
            Version applied to this request. It wins over your account's pinned
            version — see [Versioning](/using-the-api/versioning).
          schema:
            type: string
            example: '2026-04-14'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - client_id
                - password
              properties:
                client_id:
                  type: string
                  description: Your client id (a UUID). Kira gives you this value.
                  example: 00000000-0001-0000-0000-001122334455
                password:
                  type: string
                  description: >-
                    The password for your integration credentials. Kira gives
                    you this value. Letters and digits only.
                  example: yourPasswordHere
                  pattern: ^[A-Za-z0-9]+$
            examples:
              get-access-token:
                summary: Log in
                value:
                  client_id: 00000000-0001-0000-0000-001122334455
                  password: yourPasswordHere
      responses:
        '200':
          description: You are logged in. The token is in `data.access_token`.
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                  data:
                    $ref: '#/components/schemas/AuthResponse'
              example:
                message: Auth token
                data:
                  access_token: eyJ…
                  expires_in: 3600
                  token_type: Bearer
        '403':
          description: >-
            Your `x-api-key` header is missing or wrong. It is required on this
            call too, even though this is the call that logs you in.


            The message talks about routing because it is a generic body reused
            for several rejections. On this endpoint, read it as a problem with
            the api key.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                code: invalid_request
                message: >-
                  The request could not be matched to a valid route, or was
                  malformed. Verify the path and HTTP method against the API
                  reference. This is a routing or request error, not a
                  credentials or signature problem.
        '422':
          description: >-
            A field is missing, or its value is not in the form the endpoint
            accepts. `data` carries one entry per problem: `loc` is the field,
            `msg` says what is wrong.
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    description: A short label for the failure.
                    example: Invalid input data
                  data:
                    type: array
                    description: One entry per rejected field.
                    items:
                      type: object
                      properties:
                        type:
                          type: string
                          description: The kind of problem, as a machine-readable label.
                        loc:
                          type: string
                          description: >-
                            Where the problem is, as a dotted path — for example
                            `body.password`.
                        msg:
                          type: string
                          description: What is wrong, in words.
              example:
                message: Invalid input data
                data:
                  - type: string_pattern_mismatch
                    loc: body.password
                    msg: String should match pattern '^[A-Za-z0-9]+$'
      security:
        - apiKeyAuth: []
      servers:
        - url: https://api.balampay.com/sandbox
          description: Sandbox
        - url: https://api.balampay.com
          description: Production
components:
  schemas:
    AuthResponse:
      description: >-
        The token payload. It arrives **nested under `data`** — read
        `data.access_token`.
      type: object
      properties:
        access_token:
          type: string
          description: >-
            The bearer token. Send it as `Authorization: Bearer <access_token>`
            on every other call.
        token_type:
          type: string
          description: Always `Bearer`.
        expires_in:
          type: number
          description: How long the token lasts, in seconds.
          example: 3600
    ErrorResponse:
      type: object
      properties:
        message:
          type: string
        code:
          type: string
        statusCode:
          type: number
        error:
          type: string
        timestamp:
          type: string
        path:
          type: string
        details: {}
      required:
        - message
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        The `data.access_token` value from [Get access
        token](/api-reference/authentication/get-access-token).
    apiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key
      description: API key issued by Kira.

````