Quickstart & Authentication
Authenticate with the Depa API and make your first authenticated request.
All requests to the Depa API require authentication using a JSON Web Token (JWT) Bearer token in the Authorization header.
1. Obtaining a Token
To generate an authentication token, make a POST request to the /sign_in endpoint using your registered credentials.
Request
curl -X POST https://sandbox.depasify.com/api/v1/sign_in \
-H "Content-Type: application/json" \
-d '{
"email": "developer@yourcompany.com",
"password": "your_secure_password"
}'If two-factor authentication is enabled for the user, add the current code from their authenticator app as "otp_attempt".
Response
{
"data": {
"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VyX3V1aWQiOiI3ZGU4OWQ2Mi0xNjBiLTRkMTItYTdiMS1kM2IzYWM4MmM5MTAiLCJtYWluX2FjY291bnRfdXVpZCI6ImMxMmU3MzE3LTcyYzctNDFjNy1iMmFjLTJkMGI3NmYyMzUwYyIsInJvbGVzIjpbIm1haW4iLCJzZXBhIiwidHJhbnNhY3Rpb25fbW9uaXRvcmluZyJdLCJleHAiOjE3NzU0ODc5NTN9.signature"
}
}The returned token contains information about your user UUID, main account UUID, granted permissions, and token expiration (exp).
2. Authenticating Requests
Include the token in the Authorization header of all subsequent API calls prefixed by Bearer :
Authorization: Bearer <your_jwt_token>Token Expiration
Tokens are time-limited. When a token expires, requests will return 401 Unauthorized. Your client application should catch 401 errors and re-authenticate via /sign_in to receive a fresh token.
3. Your First API Call
Once authenticated, fetch the accounts linked to your client entity:
cURL
curl -X GET https://sandbox.depasify.com/api/v1/accounts \
-H "Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI..." \
-H "Accept: application/json"Node.js / TypeScript
const BASE_URL = "https://sandbox.depasify.com/api/v1";
async function getAccounts(token: string) {
const response = await fetch(`${BASE_URL}/accounts`, {
method: "GET",
headers: {
Authorization: `Bearer ${token}`,
Accept: "application/json",
},
});
if (!response.ok) {
throw new Error(`API Error: ${response.status} ${response.statusText}`);
}
const data = await response.json();
return data;
}Python
import requests
BASE_URL = "https://sandbox.depasify.com/api/v1"
def list_accounts(token: str):
headers = {
"Authorization": f"Bearer {token}",
"Accept": "application/json",
}
response = requests.get(f"{BASE_URL}/accounts", headers=headers)
response.raise_for_status()
return response.json()Entity Concepts
When integrating Depa, you will interact with three core abstractions:
- Client: The primary business contract holding one or more accounts and users.
- User: An individual, machine, or service account that signs in and executes actions within granted permission scopes.
- Account: An ownership unit that holds fiat bank accounts (IBANs), blockchain wallets, sub-accounts, and ledger balances.