Depa LogoDocsv1
Getting Started

Quickstart & Authentication

Authenticate with the Depa API and make your first authenticated request.

All requests to the Depa API require authentication using a JSON Web Token (JWT) Bearer token in the Authorization header.

1. Obtaining a Token

To generate an authentication token, make a POST request to the /sign_in endpoint using your registered credentials.

Request

curl -X POST https://sandbox.depasify.com/api/v1/sign_in \
  -H "Content-Type: application/json" \
  -d '{
    "email": "developer@yourcompany.com",
    "password": "your_secure_password"
  }'

If two-factor authentication is enabled for the user, add the current code from their authenticator app as "otp_attempt".

Response

{
  "data": {
    "token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VyX3V1aWQiOiI3ZGU4OWQ2Mi0xNjBiLTRkMTItYTdiMS1kM2IzYWM4MmM5MTAiLCJtYWluX2FjY291bnRfdXVpZCI6ImMxMmU3MzE3LTcyYzctNDFjNy1iMmFjLTJkMGI3NmYyMzUwYyIsInJvbGVzIjpbIm1haW4iLCJzZXBhIiwidHJhbnNhY3Rpb25fbW9uaXRvcmluZyJdLCJleHAiOjE3NzU0ODc5NTN9.signature"
  }
}

The returned token contains information about your user UUID, main account UUID, granted permissions, and token expiration (exp).


2. Authenticating Requests

Include the token in the Authorization header of all subsequent API calls prefixed by Bearer :

Authorization: Bearer <your_jwt_token>

Token Expiration

Tokens are time-limited. When a token expires, requests will return 401 Unauthorized. Your client application should catch 401 errors and re-authenticate via /sign_in to receive a fresh token.


3. Your First API Call

Once authenticated, fetch the accounts linked to your client entity:

cURL

curl -X GET https://sandbox.depasify.com/api/v1/accounts \
  -H "Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI..." \
  -H "Accept: application/json"

Node.js / TypeScript

const BASE_URL = "https://sandbox.depasify.com/api/v1";

async function getAccounts(token: string) {
  const response = await fetch(`${BASE_URL}/accounts`, {
    method: "GET",
    headers: {
      Authorization: `Bearer ${token}`,
      Accept: "application/json",
    },
  });

  if (!response.ok) {
    throw new Error(`API Error: ${response.status} ${response.statusText}`);
  }

  const data = await response.json();
  return data;
}

Python

import requests

BASE_URL = "https://sandbox.depasify.com/api/v1"

def list_accounts(token: str):
    headers = {
        "Authorization": f"Bearer {token}",
        "Accept": "application/json",
    }
    response = requests.get(f"{BASE_URL}/accounts", headers=headers)
    response.raise_for_status()
    return response.json()

Entity Concepts

When integrating Depa, you will interact with three core abstractions:

  • Client: The primary business contract holding one or more accounts and users.
  • User: An individual, machine, or service account that signs in and executes actions within granted permission scopes.
  • Account: An ownership unit that holds fiat bank accounts (IBANs), blockchain wallets, sub-accounts, and ledger balances.

On this page

🍪 We do not track your behaviour or use any cookie on this site.