1. Authorization
Kobble
  • Introduction
  • API Fundamentals
    • Idempotency
    • Rate Limits
    • Healthcheck
      GET
  • Authorization
    • Authorization
    • Get access token
      POST
  • Beneficiaries
    • List all beneficiaries
      GET
    • Get beneficiary by ID
      GET
    • Create beneficiary
      POST
    • Create Payid beneficiary
      POST
    • Update beneficiary
      PATCH
  • Cards
    • Cards API
    • Card Creation Flow — Developer Guide & Onboarding
    • Get all cards
      GET
    • Create a new card
      POST
    • Get card by ID
      GET
    • Update card status
      PATCH
    • Replace or renew card
      POST
    • Generate card secret
      POST
    • Generate MeaWallet widget session token
      POST
  • Card Programs
    • Card Programs API
    • Get all programs
      GET
    • Create a new program
      POST
    • Get program by ID
      GET
  • Clients
    • Clients API
    • Get all clients
    • Get client by ID
    • Create a new client
    • Update client status
  • Endusers
    • Endusers API
    • Usage of Metadata on Endusers
    • Get all endusers
    • Create a new enduser
    • Get enduser by ID
    • Update enduser
    • Create a stakeholder
    • List stakeholders
    • Update stakeholder
  • Transactions
    • Transactions API
    • Get all transactions
    • Create a transaction
    • Get transaction by ID
    • Create manual credit transaction
    • Create manual debit transaction
  • Wallets
    • Wallets API
    • Get all wallets
    • Create a new wallet
    • Get wallet by ID
    • Update wallet
  • Relays
    • Relays API
    • Create subscription
  • Webhooks
    • Webhooks API
    • Webhook Signature Verification
    • Create a webhook
    • Report completed
    • Get all webhooks
    • Delete a webhook
  • Wallet Statements
    • Request a wallet statement
    • List wallet statements
    • Get a wallet statement
    • Get a wallet statement download URL
  • Card Art
    • Get a card art upload URL
    • Register a card art
    • List card arts
    • Get a card art
    • Update a card art
    • Activate a card art
    • Archive a card art
  • Verifications
    • List verifications for a subject
    • Create a verification
    • Get a Sum Sub SDK session token
    • Get verification by ID
    • Record a client-asserted outcome
  • Transaction Documents
    • Request a presigned upload for a supporting document
    • List the supporting documents on a transaction
  • Schemas
    • Schemas
    • CardWidgetSessionTokenResponse
    • 202 Accepted
    • Webhook
    • 201 Created
    • Relay
    • Create Beneficiary with bank details
    • Client
    • Beneficiary
    • Card
    • CardCreateInputDto
    • CardStatusUpdateDto
    • CardRenewReplaceInputDto
    • Program
    • MetadataKobbleDebit1
    • ProgramCreateInputDto
    • Person
    • Company
    • Enduser
    • Enduser Create Person Input
    • Enduser Create Company Input
    • Metadata
    • Enduser Create Input DTO
    • Transaction
    • TransactionCreateManualCreditInputDto
    • TransactionDocumentType
    • TransactionDocumentStatus
    • TransactionDocumentCreateInput
    • WalletUpdateInputDto
    • TransactionDocumentUpload
    • WalletStatement
    • TransactionDocument
    • TransactionCreateInputDto
    • Wallet
    • ReportCompletedEntity
    • WalletCreateInputDto
    • ReportCompletedNotification
    • CardArt
    • CardArtDetail
    • WebhookNotification
    • CardArtUploadUrlInput
    • CardArtUploadUrlResponse
    • CardArtCreateInput
    • CardArtPatchInput
    • Error
    • RelayCreateResponse
    • ScreeningSummary
    • Verification
    • VerificationPartyLink
    • VerificationSessionToken
    • Address
    • Stakeholder
    • StakeholderCreateInput
    • StakeholderUpdateInput
  1. Authorization

Get access token

POST
/oauth2/token
Generate an access token for all other Kobble APIs.
Send this request to the Cognito host for your environment, not to the API base URL. The path below is shown without a host because this endpoint is not served from the API host.
Production: https://cognito.apikobble.net/oauth2/token
Staging: https://cognito.staging.apikobble.net/oauth2/token
Tokens are valid for 3600 seconds. The response carries no refresh token, so request a new token before the current one expires.
This endpoint and GET /customers/v1/health are the only two that require no authentication.

Request

Header Params

Body Params application/x-www-form-urlencoded

Request Code Samples

Shell
JavaScript
Java
Swift
Go
PHP
Python
HTTP
C
C#
Objective-C
Ruby
OCaml
Dart
R
Request Request Example
Shell
JavaScript
Java
Swift
curl --location '/oauth2/token' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode 'grant_type=client_credentials' \
--data-urlencode 'client_id={{client_id}}' \
--data-urlencode 'scope=administrator/write' \
--data-urlencode 'client_secret={{client_secret}}'

Responses

🟢200OK
application/json
Bodyapplication/json

Example
{
    "access_token": "eyJraWQiOiJFWEFNUExFIn0.eyJzdWIiOiJleGFtcGxlIn0.EXAMPLE-SIGNATURE",
    "expires_in": 3600,
    "token_type": "Bearer"
}
Modified at 2026-09-16 03:02:46
Previous
Authorization
Next
List all beneficiaries
Built with