Paymob Authentication API

The Authentication API from Paymob — 3 operation(s) for authentication.

OpenAPI Specification

paymob-authentication-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: Paymob Accept Legacy (v2) Accounts Authentication API
  version: '2.0'
  description: 'The legacy Paymob Accept API uses a three-step flow: authenticate to receive a bearer auth_token, register an order, then request a payment_key. The payment_key is used either with the iframe redirect or the headless /payments/pay endpoint. Refund, void, capture, transaction inquiry, and saved-card MOTO operations are exposed on this surface.'
  contact:
    name: Paymob Developers
    url: https://developers.paymob.com
servers:
- url: https://accept.paymob.com
  description: Egypt production
- url: https://ksa.paymob.com
  description: Saudi Arabia production
- url: https://uae.paymob.com
  description: UAE production
- url: https://oman.paymob.com
  description: Oman production
- url: https://pakistan.paymob.com
  description: Pakistan production
security:
- BearerAuth: []
tags:
- name: Authentication
paths:
  /api/auth/tokens:
    post:
      summary: Authenticate Merchant
      operationId: createAuthToken
      tags:
      - Authentication
      description: Exchange the merchant API key for a short-lived auth_token (60 minutes).
      security: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
              - api_key
              properties:
                api_key:
                  type: string
      responses:
        '201':
          description: Token created
          content:
            application/json:
              schema:
                type: object
                properties:
                  token:
                    type: string
                  profile:
                    type: object
                    additionalProperties: true
  /api/auth/token/:
    post:
      summary: Generate Access Token
      operationId: generatePayoutsToken
      tags:
      - Authentication
      description: Generate an OAuth2 access token. Token must be refreshed every 60 minutes.
      security: []
      requestBody:
        required: true
        content:
          application/x-www-form-urlencoded:
            schema:
              type: object
              required:
              - username
              - password
              - grant_type
              - client_id
              - client_secret
              properties:
                grant_type:
                  type: string
                  enum:
                  - password
                username:
                  type: string
                password:
                  type: string
                client_id:
                  type: string
                client_secret:
                  type: string
      responses:
        '200':
          description: Token issued
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Token'
  /api/auth/token/refresh/:
    post:
      summary: Refresh Access Token
      operationId: refreshPayoutsToken
      tags:
      - Authentication
      security: []
      requestBody:
        required: true
        content:
          application/x-www-form-urlencoded:
            schema:
              type: object
              required:
              - refresh_token
              - grant_type
              - client_id
              - client_secret
              properties:
                grant_type:
                  type: string
                  enum:
                  - refresh_token
                refresh_token:
                  type: string
                client_id:
                  type: string
                client_secret:
                  type: string
      responses:
        '200':
          description: Token refreshed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Token'
components:
  schemas:
    Token:
      type: object
      properties:
        access_token:
          type: string
        refresh_token:
          type: string
        expires_in:
          type: integer
        token_type:
          type: string
        scope:
          type: string
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: Bearer auth_token from /api/auth/tokens (60-minute TTL).