East West Bancorp · Authentication Profile
East West Bancorp Authentication
Authentication
East West Bancorp secures its APIs with oauth2 across 1 declared security scheme, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the clientCredentials flow(s).
BankingFinancial ServicesCommercial BankingTreasury ManagementOpen BankingPaymentsCross-BorderUnited States
Methods: oauth2
Schemes: 1
OAuth flows: clientCredentials
API key in:
Security Schemes
OAuth2 client credentials (Authorization API) oauth2
scheme: OAuth 2.0 Authorization Framework, two-legged / machine-to-machine
· flows: clientCredentials
Source
Authentication Profile
generated: '2026-09-14'
method: searched
source: https://apiportal.eastwestbank.com/AuthorizationAPI
docs: https://apiportal.eastwestbank.com/AuthorizationAPI
note: >-
East West Bancorp publishes no API of its own; the group's API surface is the Bridge Open
Banking program operated by its banking subsidiary, East West Bank, at
apiportal.eastwestbank.com. No OpenAPI or Swagger document is publicly downloadable — the
API list, product library and reference render only after portal sign-in — so this profile
is transcribed from the two pages the provider serves anonymously: the Authorization API
page (which carries the full token exchange, including the literal token endpoint) and the
portal FAQ. Nothing here is derived from a securityScheme, because there is no public spec.
summary:
types:
- oauth2
oauth2_flows:
- clientCredentials
api_key_in: []
bearer: true
schemes:
- name: OAuth2 client credentials (Authorization API)
type: oauth2
scheme: OAuth 2.0 Authorization Framework, two-legged / machine-to-machine
sources:
- https://apiportal.eastwestbank.com/AuthorizationAPI
- https://apiportal.eastwestbank.com/faqs
flows:
- flow: clientCredentials
token_url: https://ewbpoc.okta.com/oauth2/ausdaetdg9zY8EZuI2p6/v1/token
token_url_status: >-
Published verbatim by the provider. Probed 2026-09-14: the Okta authorization-server
metadata for this server id returns 404 (Okta "Page Not Found"), and the org slug
"ewbpoc" reads as a proof-of-concept tenant, so the documented endpoint may be stale.
Recorded as the provider states it; not corrected, not guessed.
grant_type: client_credentials
request_content_type: application/x-www-form-urlencoded
parameters:
- client_id
- client_secret
- grant_type
response_fields:
- access_token
- token_type
- expires_in
token_type: Bearer
expires_in_seconds: 86400
note: >-
Identity provider is Okta. The Authorization API page shows the token call with
client_id and client_secret in the form body; the portal FAQ additionally documents
base-64 encoding the ClientID and ClientSecret and prefixing "Basic " on the token
call, so both credential presentations appear in the provider's own documentation.
credentials:
client_id: issued per application created in the developer portal
client_secret: issued per application created in the developer portal
encoding: >-
Base-64 encode ClientID and ClientSecret; the FAQ recommends encoding in application
logic rather than storing a static encoded string, and requires the "Basic" prefix on
the token call.
application_model: >-
An "application" is a collection of one or more API resources reachable with a single
authentication credential. A developer must create one before calling the sandbox.
request_authorization:
header: Authorization
format: 'Bearer <access_token>'
applies_to: every protected API endpoint
transport_security:
client_certificate_required: true
scope: >-
A client certificate is required for connectivity to the sandbox and production
environments; no certificate is needed to browse the Bridge Open Banking portal.
Certificates and access credentials are issued by East West Bank GTS during onboarding.
source: https://apiportal.eastwestbank.com/faqs
troubleshooting:
- status: 401
title: Unauthorized
causes:
- client-id and secret not correctly matched against the application that was created
- base-64 encoding not formatted per the authorization documentation
- '"Basic" not prefixed to the encoded ClientID and ClientSecret on the token call'
- access token invalidated or expired
source: https://apiportal.eastwestbank.com/faqs
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/east-west-bancorp-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.