How to access the API

Register an app in the B2CORE IB Back Office, choose its access level, exchange the credentials for an access token and call the IB API

Integrations access the B2CORE IB API on behalf of an app registered in the Back Office. Each app has a Client ID, a Client secret and an access level that defines whether the app can change data. This article shows how to register an app and make your first API call.

Register an app

Go to Introducing brokers > Preferences > Apps.

Click Register a New App.

Specify an App name in the App Name field.

Select the Access level:

  • Read-only (pre-selected) — the app can call every GET operation and create export jobs; any other POST, PUT, PATCH or DELETE request made with the app's access token is rejected. Recommended for reporting and monitoring integrations.
  • Full access — the app can call every API operation.

You can change the access level later on the app details page. The change applies to the app's next API request.

Click Save.

You are redirected to the page with the details of the newly created app, where you can view App name, Client ID, Client secret, Access level and IP Whitelist.

Copy your Client ID and Client secret and keep them in a secure storage. They are used to verify your identity when accessing the API. The Client secret is shown only once, on this page — you can't view it again later.

Get an access token

Send a POST request to the /tokens operation using HTTP Basic authentication, with the Client ID as the username and the Client secret as the password:

curl -X POST "{baseUrl}/tokens" \
  -u "CLIENT_ID:CLIENT_SECRET" \
  -H "Content-Type: application/json" \
  -d '{"grant_type": "client_credentials"}'

Replace {baseUrl} with the base URL of your IB API, which is provided by your B2BROKER integration team.

Copy the access_token value from the response. The response also contains token_type (Bearer) and expires_in — the token lifetime in seconds. Requesting a new token revokes the app's earlier tokens.

Call the API

Pass the token in the Authorization header of every request:

curl "{baseUrl}/users" \
  -H "Authorization: Bearer ACCESS_TOKEN"

All operations are listed in the API reference. Each operation shows the access it requires: read (available to every app) or write (Full-access apps only).

What a 403 response means

If a read-only app calls an operation that requires write access, the API rejects the request with HTTP 403 and the following body:

{
  "error": {
    "message": "This App is read-only and cannot perform this operation.",
    "code": "insufficient_scope"
  }
}

Check the code field: insufficient_scope means that the app's access level is the cause. To make the request succeed, either switch the app to Full access in Introducing brokers > Preferences > Apps — the change applies to the next request, no new token is needed — or register a separate Full-access app for the integration that needs to change data.

The one exception is POST /exports/async: creating an export job is allowed for read-only apps, so reporting integrations can export data without Full access.

Zuletzt aktualisiert am

Auf dieser Seite