Authentication

Getting credentials

Tokens are issued by the ChargeNow team. To get started, contact us with your organisation name and a brief description of what you're building. We'll create an integration and issue your first token.

For sandbox access, see the Sandbox guide.

Making authenticated requests

Include your token as a Bearer token in the Authorization header of every request. All requests without a valid token are rejected.

Token lifecycle

Tokens have a long validity period and are also active until explicitly revoked. We'll tell you the exact expiry when we issue your token.

To rotate or revoke a token, contact us. We recommend rotating tokens periodically and immediately if you suspect a token has been compromised.

Keep your token secret. Do not commit it to source control or expose it in client-side code.

Authentication errors

If a request fails due to authentication, you will receive a 401 response. The most common causes are a missing token, an expired token, or a token that has been revoked. See the Errors guide for how to handle these.