> ## Documentation Index
> Fetch the complete documentation index at: https://docs.repediu.com.br/llms.txt
> Use this file to discover all available pages before exploring further.

# Obter token

> Autentique-se com clientId e clientSecret e receba um Bearer token válido por 6 horas

Esta rota é a autenticação da API de **Envio de Dados** — não confunda com o token `client_credentials` da API Open Delivery deste site: são fluxos, tokens e escopos diferentes, sem intercambialidade.

<Steps>
  <Step title="Receba suas credenciais">
    O `clientId` (código da empresa) e o `clientSecret` (chave da empresa) são obtidos em [app.repediu.com.br/integrations](https://app.repediu.com.br/integrations). Não há autocadastro — sem acesso, fale com o suporte técnico.
  </Step>

  <Step title="Solicite o token">
    Envie um `POST` com corpo **JSON em camelCase**: `{"clientId": <número>, "clientSecret": "<string>"}`.
  </Step>

  <Step title="Use o token">
    Envie o `token` retornado no header `Authorization: Bearer <token>` nas chamadas de [Enviar venda](/envio-de-dados/enviar-venda), [Atualizar clientes](/envio-de-dados/atualizar-clientes), [Avaliação de pedido](/envio-de-dados/avaliacao-pedido) e [Cashback](/envio-de-dados/cashback).
  </Step>

  <Step title="Renove após 6 horas">
    O token expira em **21600 segundos (6 horas fixas)** — não há refresh token. Guarde o token e gere um novo somente ao expirar ou receber `401`.
  </Step>
</Steps>

<Warning>
  O campo é `clientId` (camelCase), **não** `client_id` (snake\_case). O JSON usa correspondência de nome insensível a maiúsculas/minúsculas, mas não ignora underscores — enviar `client_id`/`client_secret` não retorna erro, apenas falha silenciosamente (o campo chega vazio no servidor e a autenticação é recusada como credencial inválida).
</Warning>

<Info>
  Esta rota **não tem rate limit** — diferente de todas as outras rotas desta API, que aceitam no máximo 60 requisições/minuto por token.
</Info>

## Erros

| HTTP | Mensagem em `error.message` | Quando acontece |
| - | - | - |
| `400` | `Invalid client_id or client_secret.` | `clientId` inexistente ou `clientSecret` incorreto |
| `400` | `More than one integration with same secret for company.` | Ambiguidade de credencial — mais de uma integração ativa com o mesmo `clientSecret` |
| `404` | `Company is inactive.` | Empresa encontrada, mas inativa |

## Exemplo

<CodeGroup>
  ```bash Solicitar token theme={null}
  curl --request POST \
    --url https://public-api.repediu.com.br/authentication/users/accessToken \
    --header 'Content-Type: application/json' \
    --data '{
      "clientId": 12345,
      "clientSecret": "e78720b6-55d5-4985-9d7c-34b64297eb4e"
    }'
  ```
</CodeGroup>

<Card title="Enviar venda" icon="receipt" href="/envio-de-dados/enviar-venda">
  Com o token em mãos, o próximo passo é enviar o histórico de vendas.
</Card>


## OpenAPI

````yaml openapi-envio-de-dados.yaml POST /authentication/users/accessToken
openapi: 3.0.1
info:
  title: Repediu — API de Envio de Dados
  description: >-
    API para o parceiro ENVIAR dados para a Repediu (vendas, clientes,
    avaliações e cashback) — sentido inverso ao da API Open Delivery, onde o
    parceiro LÊ dados da Repediu. Autenticação própria via
    clientId/clientSecret, sem relação com o token client_credentials do Open
    Delivery.
  version: v1
servers:
  - url: https://public-api.repediu.com.br
    description: Produção
security:
  - Bearer: []
paths:
  /authentication/users/accessToken:
    post:
      tags:
        - Autenticação
      summary: Obter token de acesso
      description: >-
        Emite um token de acesso (JWT) válido por 6 horas fixas, a partir do
        clientId e clientSecret da empresa. Não há refresh token nem rate limit
        nesta rota.
      operationId: createIntegrationAccessToken
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateAccessTokenRequest'
            example:
              clientId: 12345
              clientSecret: e78720b6-55d5-4985-9d7c-34b64297eb4e
      responses:
        '200':
          description: Token emitido com sucesso.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccessTokenEnvelope'
              example:
                result:
                  token: >-
                    eyJhbGciOiJIUzI1NiIsInR5cCI6ImJlYXJlciJ9.eyJjb21wYW55X2lkIjoiNTA3In0.assinatura
                  type: bearer
                  expiresIn: 21600
                error: null
                timeGenerated: '2025-09-26T18:36:03.0791284Z'
                success: true
        '400':
          description: >-
            Campo obrigatório ausente, client_id/client_secret com mais de uma
            integração vinculada.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StringEnvelope'
              example:
                result: null
                error:
                  message: Invalid client_id or client_secret.
                  notifications: null
                  errorDetails: null
                timeGenerated: '2025-09-26T18:36:03.0791284Z'
                success: false
        '404':
          description: Empresa inativa.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StringEnvelope'
              example:
                result: null
                error:
                  message: Company is inactive.
                  notifications: null
                  errorDetails: null
                timeGenerated: '2025-09-26T18:36:03.0791284Z'
                success: false
      security: []
components:
  schemas:
    CreateAccessTokenRequest:
      type: object
      required:
        - clientId
        - clientSecret
      properties:
        clientId:
          type: integer
          format: int32
        clientSecret:
          type: string
    AccessTokenEnvelope:
      type: object
      properties:
        result:
          $ref: '#/components/schemas/CreateAccessTokenResponse'
        error:
          $ref: '#/components/schemas/EnvelopeError'
        timeGenerated:
          type: string
          format: date-time
        success:
          type: boolean
    StringEnvelope:
      type: object
      properties:
        result:
          type: string
          nullable: true
        error:
          $ref: '#/components/schemas/EnvelopeError'
        timeGenerated:
          type: string
          format: date-time
        success:
          type: boolean
    CreateAccessTokenResponse:
      type: object
      properties:
        token:
          type: string
        type:
          type: string
          description: Sempre "bearer".
        expiresIn:
          type: integer
          format: int32
          description: Segundos até expirar — sempre 21600 (6 horas).
    EnvelopeError:
      type: object
      nullable: true
      properties:
        message:
          type: string
        notifications:
          type: array
          nullable: true
          items:
            type: object
            properties:
              key:
                type: string
              message:
                type: string
        errorDetails:
          nullable: true
          description: Formato livre — string, objeto ou array dependendo do erro.
  securitySchemes:
    Bearer:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Token emitido por POST /authentication/users/accessToken. Envie no
        header Authorization como `Bearer <token>`. Válido por 6 horas.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.