Lorum · Authentication Profile

Lorum Authentication

Authentication

Lorum secures its APIs with oauth2 and http across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the clientCredentials flow(s).

CompanyFintechPaymentsBankingClearingSettlementTreasuryMulti-CurrencyAccountsForeign ExchangeWebhooks
Methods: oauth2, http Schemes: 2 OAuth flows: clientCredentials API key in:

Security Schemes

OAuth2 http
scheme: bearer
ClientCredentials oauth2

Source

Authentication Profile

Raw ↑
generated: '2026-07-20'
method: searched
source: openapi/lorum-openapi-original.json
docs: https://docs.lorum.com/docs/authenticating-to-the-api
summary:
  types:
  - oauth2
  - http
  oauth2_flows:
  - clientCredentials
  api_key_in: []
  notes: >-
    Lorum (Fuse) uses the OAuth 2.0 client credentials grant to mint a JWT
    bearer access_token, which is then presented as `Authorization: Bearer
    <token>` on every API call. Tokens are valid for 3 hours and MUST be cached
    and reused - integrations that request a new token per call are not
    certified for production. The authorization server is Auth0-backed.
schemes:
- name: OAuth2
  type: http
  scheme: bearer
  bearerFormat: JWT
  sources:
  - openapi/lorum-openapi-original.json
- name: ClientCredentials
  type: oauth2
  flow: clientCredentials
  token_url_production: https://auth.fuse.me/oauth/token
  token_url_sandbox: https://auth-sandbox.fuse.me/oauth/token
  audience_default: https://api.fuse.me
  token_lifetime_seconds: 10800
  issuer: https://auth.fuse.me/
  provider: auth0
  source: https://docs.lorum.com/docs/authenticating-to-the-api