Access token validation endpoint
When you integrate our solution, we request that you create and communicate to us a new access token validation endpoint.
The aim of this endpoint is for us to be able to validate the access token of a given member in your system (external token), when you request us to generate a new access token for this member - see Get an access token.
We will send you the member's external token we have received in your request for you to check if it matches the one you would have sent us.
How does it work?
When you send a request to get an access token for a given member id or member external id (see Get an access token), before generating the member's access token, we need to validate the member's external token.
In order to proceed with this verification, we will send a GET request to the endpoint you provided with the following header parameters:
Expires-at- request expiration time as a UNIX timestamp in UTC timezone. We use +1 minute from the current time.Signature-base64encodedSHA256signature of the string represented asx-access-token|Api-Key|Expires-at|, 3 parameters concatenated with a vertical bar|, signed with Spaycial's private key.Content-Type-application/json.Accept-application/json.x-access-token- the member's access token in your system.Api-Key- the API key used to call the Spaycial API.customerExternalId- the member's external id.
If the member's external token is validated (meaning we get a successful response from your endpoint), we will generate a new access token for this member. Otherwise, we will return an error.
Examples
Validation endpoint to be provided to us
https://www.api.yourdomain.com/mymall/tc-endpoint
Headers to be received by your endpoint
{
"expires-at": "1623406378",
"signature": "iv2MYg/u94gKX1qgSS2+m0KJwYGUNAiMh4kXs2KzrtczdrCiby4nj8+b/Lmk5VP/BKkU71VKE0vyiskjif6XFzlhgTun4IIPCHBmVMmfzWt4U19h01Zs18YVxqDX3fGMj6sdOLES7qarMMxdcD1fS8MilFOZTeBj/eoLpArHL3cAHQ/snu2yidGG+3A3JX77Rrp947ZR+joO5cDFn6qTkSeaxDof2oWNJLDR8dzM8OystbDOhSU2HIe4BokC5mBYreT2lKTH5KOpw9Nz4LP9yaHHwnyo/X0PA9l6u7ZyknnQtlTFh9wIQyOIgDJsPiuvW3z6xfvwj9JsWrOsMxcwWQ==",
"content-type": "application/json",
"accept": "application/json",
"x-access-token": "123456789",
"api-key": "17fe12345cc783a16b2070b1eaa382dki"
}