Atomic Access Tokens API

The Access Tokens API from Atomic — 2 operation(s) for access tokens.

OpenAPI Specification

atomic-fi-access-tokens-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: Atomic Access Tokens API
  description: Representative OpenAPI description of Atomic's payroll and financial connectivity API (UserLink and PayLink). Atomic lets applications switch direct deposit, verify income and employment, retrieve payroll data, and update payment methods on file through user-permissioned access. The Transact SDK is an embedded, hosted front-end launched with a publicToken that drives deposit, verify, and tax task workflows on top of these endpoints. This is a faithful, non-exhaustive representation authored by API Evangelist from public documentation, not an official Atomic artifact.
  termsOfService: https://atomicfi.com/legal
  contact:
    name: Atomic Support
    url: https://docs.atomicfi.com
  version: '1.0'
servers:
- url: https://api.atomicfi.com
  description: Production
- url: https://sandbox-api.atomicfi.com
  description: Sandbox
- url: https://pci.atomicfi.com
  description: Production PCI host (PayLink card data)
- url: https://sandbox-pci.atomicfi.com
  description: Sandbox PCI host (PayLink card data)
security:
- ApiKeyAuth: []
tags:
- name: Access Tokens
paths:
  /access-token:
    post:
      operationId: createAccessToken
      tags:
      - Access Tokens
      summary: Create an access token
      description: Exchanges your API Key and Secret for a publicToken used to initialize the Transact SDK on the client. Called from your backend.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateAccessTokenRequest'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccessTokenResponse'
  /access-token/{publicToken}/revoke:
    put:
      operationId: revokeAccessToken
      tags:
      - Access Tokens
      summary: Revoke an access token
      description: Invalidates an existing publicToken so it can no longer access API resources.
      parameters:
      - $ref: '#/components/parameters/PublicTokenPath'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuccessResult'
components:
  schemas:
    SuccessResult:
      type: object
      properties:
        result:
          type: object
          properties:
            success:
              type: boolean
        success:
          type: boolean
    AccessTokenResponse:
      type: object
      properties:
        data:
          type: object
          properties:
            publicToken:
              type: string
    CreateAccessTokenRequest:
      type: object
      required:
      - identifier
      properties:
        identifier:
          type: string
          description: Your unique identifier for the end user.
        tokenLifetime:
          type: integer
          description: Lifetime of the returned publicToken in seconds.
          example: 86400
  parameters:
    PublicTokenPath:
      name: publicToken
      in: path
      required: true
      schema:
        type: string
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key
      description: API Key sent in the x-api-key header, paired with the x-api-secret header. Used for backend-to-backend calls.
    PublicTokenAuth:
      type: apiKey
      in: header
      name: x-public-token
      description: Public token for permitted client-side requests.
Where this information came from

This is an independent, third-party profile of Atomic Access Tokens API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.