# Get Access Token

Requests new access token for accessing Keeta API resources. 
**If you have completed the development in full compliance with the Open Delivery native protocol's `grant_type=client_credentials`, please contact Keeta.**
**If you have already completed development using `grant_type=client_credentials` and have passed SIT certification or are already in production, you can continue to use `grant_type=client_credentials` without any impact.**
> **IMPORTANT:**  The Software Service must obtain the merchant’s authorization before accessing their data.

##### APP Level Token mode
1. **Application-level access_token**: The access_token can be used to access all stores authorized
2. **grant_type = app_level_token**: Generate and refresh access_token

##### Shop Level Authorization Code mode
1. **Store-level access_token**: The access_token can be used to access one store authorized
2. **grant_type = shop_level_authorization_code**: Use `authorization_code` to generate access_token, and return `refresh_token` for subsequent refresh
3. **grant_type = refresh_toke**n: Use this parameter to refresh a new `access_token` and `refresh_token`, before the old `access_token` expires.

HOST: **Keeta**
DIRECTION:

Endpoint: POST /oauth/token
Version: v.1.0.7

## Description:

  - `APP Level Token mode` ()
    Application-level access_token: The access_token can be used to access all stores authorizedgrant_type = app_level_token: Generate and refresh access_token

  - `Shop Level Authorization Code mode` ()
    Store-level access_token: The access_token can be used to access one store authorizedgrant_type = shop_level_authorization_code: Use authorization_code to generate access_token, and return refresh_token for subsequent refreshgrant_type = refresh_token: Use this parameter to refresh a new access_token and refresh_token, before the old access_token expires. HOST: Keeta DIRECTION:

## Request fields (application/json):

  - `client_id` (string, required)
    Client identifier provided by Keeta.

  - `grant_type` (string, required)
    The OAuth grant type.
    Enum: "app_level_token"

  - `client_secret` (string, required)
    Client Secret provided by Keeta.(When `grant_type = app_level_token`, this field needs to be filled in)

  - `authorization_code` (string, required)
    When `grant_type = shop_level_authorization_code`, this field needs to be filled in

  - `refresh_token` (string, required)
    When `grant_type = refresh_token`, this field needs to be filled in

## Response 200:

  - `200` (unknown)
    Successful returns token request.

## Response 200 fields (application/json):

  - `access_token` (string, required)
    A code representing the access token.

  - `token_type` (string, required)
    The token type. Currently, the only supported type is bearer.
    Example: bearer

  - `expires_in` (integer)
    The token expiration time in seconds

  - `refresh_token` (string, required)
    A code representing the refresh token.
**Condition:** This field will be returned when the `grant_type` is `shop_level_authorization_code` or `refresh_token`.
When the `grant_type` is set to `app_level_token`, the response does not contain this field.

## Response 401:

  - `401` (unknown)
    Request lacks valid authentication credentials for the target resource

## Response 401 fields (application/problem+json):

  - `title` (string, required)
    Short description of the problem.
    Example: Unexpected error

  - `status` (integer, required)
    HTTP code of the returned status.
    Example: 500

## Response 503:

  - `503` (unknown)
    Service is not currently available. Requested service may be under maintenance or outside the operating window.

## Response 503 fields (application/problem+json):

  - `title` (string, required)
    Short description of the problem.
    Example: Unexpected error

  - `status` (integer, required)
    HTTP code of the returned status.
    Example: 500

