Fifth Third Bancorp Auth API

The Authentication section explains how to securely interact with Newline's API using access tokens and static IP addresses. Learn how to generate and refresh tokens to access protected resources. **Endpoints:** - POST [Generate an authentication token: POST /auth](https://developers.newline53.com/reference/post_auth) Newline requires access tokens and static IP addresses for authentication and authorization when requesting any resource endpoints. [POST /auth](https://developers.newline53.com/reference/post_auth) is used to obtain and refresh the required access tokens. Please work with your Relationship Team or the Newline Team in all environments to set up the IP Allowlist for your Program. To obtain an access token, you must submit a refresh token. After a program is set up, Newline will share your Program UID and HMAC key offline. These values are required for the refresh token and access token requests. ## Auth Flow The authentication flow is as follows: 1. Create a JWT using the following claim: ``` { "iat": , "sub": } ``` 1. Sign the JWT to create a JWS with the shared key using HS512 / SHA-512. 2. Exchange for an access token by sending a request to [POST /auth](https://developers.newline53.com/reference/post_auth), using the JWS in the `Authorization` header. 3. Access resources through other endpoints using the returned token in the `Authorization` header for up to 8 hours. 4. Repeat the process as needed to continue authenticating successfully. > **Note** > If a new access token is requested within the 8 hours of a previous token being successfully exchanged, the new token will still be generated. This does not expire the last token, and both tokens are usable simultaneously until their respective time is up. However, it is encouraged to use the new token and discard the old one if possible, as this behavior may change in the future.

Operations 1

POST /auth Generate an authentication token #

Documentation

📖
Documentation
https://developers.newline53.com/docs/api-authentication
📖
APIReference
https://developers.newline53.com/reference/post_auth
📖
APIReference
https://developers.newline53.com/reference/customers
📖
Documentation
https://developers.newline53.com/reference/overview-of-customer-types
📖
APIReference
https://developers.newline53.com/reference/customer-products
📖
Documentation
https://developers.newline53.com/reference/customer-product-statuses
📖
APIReference
https://developers.newline53.com/reference/products
📖
APIReference
https://developers.newline53.com/reference/pools
📖
APIReference
https://developers.newline53.com/reference/custodial-accounts
📖
Documentation
https://developers.newline53.com/reference/custodial-account-statuses
📖
APIReference
https://developers.newline53.com/reference/synthetic-accounts
📖
Documentation
https://developers.newline53.com/reference/synthetic-account-categories
📖
APIReference
https://developers.newline53.com/reference/transfers
📖
Documentation
https://developers.newline53.com/reference/transfer-statuses
📖
APIReference
https://developers.newline53.com/reference/combined-transfers
📖
APIReference
https://developers.newline53.com/reference/transactions
📖
Documentation
https://developers.newline53.com/reference/transaction-statuses-and-transaction-types
📖
APIReference
https://developers.newline53.com/reference/returns
📖
APIReference
https://developers.newline53.com/reference/virtual-reference-numbers
📖
Documentation
https://developers.newline53.com/reference/virtual-reference-number-statuses
📖
APIReference
https://developers.newline53.com/reference/sandbox
📖
Documentation
https://developers.newline53.com/docs/sandbox-walkthrough

Specifications

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/fifth-third-bancorp-auth-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

fifth-third-bancorp-auth-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Newline Platform Auth API
  version: 1.0.0
  description: Welcome!
servers:
- url: https://sandbox.newline53.com/api/v1
security:
- ApiKeyAuth: []
tags:
- name: Auth
  description: The Authentication section explains how to securely interact with Newline's API using access tokens and static IP addresses.
paths:
  /auth:
    parameters:
    - in: header
      name: x-trace-id
      description: 'A unique identifier provided for each request. Duplicate values submitted in requests within 7 days of each other will cause the request to be rejected.

        '
      schema:
        type: string
        example: 123e4567-e89b-12d3-a456-426614174000
      required: true
    post:
      tags:
      - Auth
      summary: Generate an authentication token
      description: 'An access token can be generated by providing a refresh token. The generated token then can be used as an authentication token to access resources for up to 8 hours.


        The Client will need to provide a JWS, its payload containing Program UID as `sub` (subject) and current Epoch time as `iat` (issued at timestamp), signed by an HMAC that has been shared offline previously using HS512. See the above guide for more details.


        When Newline processes the `POST /auth` request, it validates that the `iat` claim is current. A 30-second difference is allowed to account for clock skew. Nevertheless, it is important that the refresh token be submitted as quickly as possible after it is generated to avoid failure in receiving an access token. Note that the returned access token is a valid JWS following `auth-` and the whole value (`auth-header.payload.signature`) must be provided in the `Authorization` header when making requests to other endpoints.'
      parameters:
      - in: header
        name: Authorization
        description: Refresh token signed with shared HMAC
        schema:
          type: string
        example: header.payload.hmacsignature
        required: true
      responses:
        '201':
          description: A new authentication token is generated
          headers:
            x-trace-id:
              description: The unique identifier provided with the request.
              schema:
                type: string
                example: 123e4567-e89b-12d3-a456-426614174000
          content:
            application/json:
              schema:
                type: object
                properties:
                  token:
                    type: string
                    description: 'Access token that can be used in the `Authorization` header when sending requests to other endpoints for up to 8 hours.

                      '
                    example: auth-header.payload.signature
      operationId: postAuth
      x-operation-id-source: derived
components:
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: Authorization
      description: Access token signed with shared HMAC
x-explorer-enabled: false