---
updatedAt: 2026-04-13T12:53:44.000Z
agentTools:
  projectIndex: https://docs.veridion.com/llms.txt
---

# Authentication

Veridion APIs require authentication before you can access them. This guide explains how to authenticate using the OAuth 2.0 Client Credentials flow and how to use your access token to call the APIs.

## Overview

Authentication is the process of verifying the identity of a client application. Veridion uses **OAuth 2.0** with the **Client Credentials flow** for API authentication, which is designed for server-to-server integrations where your application authenticates itself (rather than a user).

### How It Works

<Image align="center" alt="image.png" src="https://files.readme.io/c6da2acaf37d993c2874de3a0c981d8b21d9f24a64cc8dd5f02cf51428db7787-diagram.png" />

1. Your application requests an access token from the Authorization Server using your credentials
2. The Authorization Server validates your credentials and returns an access token
3. Your application includes the access token in requests to the Veridion API
4. The API validates the token and returns the requested data

***

## Prerequisites

To authenticate with Veridion APIs, you will need the following credentials provided by your Veridion representative:

| Parameter       | Description                     |
| --------------- | ------------------------------- |
| `client_id`     | Your unique client identifier   |
| `client_secret` | Your confidential client secret |

***

## Endpoints

| Purpose            | URL                                                          |
| ------------------ | ------------------------------------------------------------ |
| Token Endpoint     | `https://auth.veridion.com/oauth2/token`                     |
| Discovery Document | `https://auth.veridion.com/.well-known/openid-configuration` |
| Veridion APIs      | `https://data.veridion.com`                                  |

***

## Token Structure

A successful authentication request returns a JSON response with the following structure:

```json
{
    "access_token": "TwmfRUlqnvSh3j...",
    "scope": "api:use",
    "token_type": "Bearer",
    "expires_in": 3599
}
```

| Field          | Description                                                                  |
| -------------- | ---------------------------------------------------------------------------- |
| `token_type`   | The type of token issued. Always `Bearer`.                                   |
| `expires_in`   | Token validity period in seconds. Tokens expire after 1 hour (3600 seconds). |
| `access_token` | The token to include in API requests.                                        |
| `scope`        | The scope granted to this token.                                             |

***

## Generating a Token

### Using Postman

### Step 1: Set Up the Token URL

Create a new request in Postman and configure it as follows:

* **Method:** `POST`
* **URL:** `https://auth.veridion.com/oauth2/token`

### Step 2: Set Up Authentication

1. Click on the **Authorization** tab
2. Select **Basic Auth** from the Type dropdown
3. Enter your credentials:
   * **Username:** Your `client_id`
   * **Password:** Your `client_secret`

<Image align="center" alt="image.png" src="https://files.readme.io/0c562e0c136e07825bcafc4e6d34d7c1ee2ed9f044234680166ea1c840dfdeec-postman1.png" />

### Step 3: Set Up the Request Body

1. Click on the **Body** tab
2. Select **x-www-form-urlencoded**
3. Add the following key-value pairs:

| Key          | Value                |
| ------------ | -------------------- |
| `grant_type` | `client_credentials` |
| `scope`      | `api:use`            |

### Step 4: Request the Token

Click **Send**. If successful, you will receive a response like this:

```json
{
    "access_token": "TwmfRUlqnvSh3j...",
    "scope": "api:use",
    "token_type": "Bearer",
    "expires_in": 3599
}
```

***

### Using cURL

```bash
curl -X POST https://auth.veridion.com/oauth2/token \
  -u "your_client_id:your_client_secret" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "grant_type=client_credentials&scope=api:use"

```

Replace `your_client_id` and `your_client_secret` with your actual credentials.

## Error Handling

<Table align={["left","left","left","left"]}>
  <thead>
    <tr>
      <th>
        HTTP Status
      </th>

      <th>
        Body
      </th>

      <th>
        Meaning
      </th>

      <th>
        Resolution
      </th>
    </tr>
  </thead>

  <tbody>
    <tr>
      <td>
        `400 Bad Request`
      </td>

      <td>
        `"error": "invalid_scope"`
      </td>

      <td>
        Bad parameters provided
      </td>

      <td>
        Scope or credentials not properly set.
      </td>
    </tr>

    <tr>
      <td>
        `401 Unauthorized`
      </td>

      <td>
        `"error": "invalid_client"`
      </td>

      <td>
        Invalid client credentials
      </td>

      <td>
        Double check your client_id and client_secret.
      </td>
    </tr>

    <tr>
      <td>
        `403 Forbidden`
      </td>

      <td>
        `"error_description": "account has not been setup.",  
        "error": "access_denied"`
      </td>

      <td>
        Your account has not been activated
      </td>

      <td>
        Contact your Veridion representative
      </td>
    </tr>

    <tr>
      <td>
        `403 Forbidden`
      </td>

      <td>
        `"error_description": "account has been disabled",  
        "error": "access_denied"`
      </td>

      <td>
        Your account is not enabled
      </td>

      <td>
        Contact your Veridion representative
      </td>
    </tr>
  </tbody>
</Table>

***

## Calling the API

Once you have obtained an access token, include it in the `Authorization` header of your API requests.

### Using Postman

### Step 1: Set Up the Request

* **Method:** `POST` (or as specified by the endpoint)
* **URL:** `https://data.veridion.com/match/v5/companies` (or your desired endpoint)

### Step 2: Add the Authorization Header

1. Click on the **Authorization** tab
2. Select **Bearer Token** from the Type dropdown
3. Paste your access token in the **Token** field

<Image align="center" alt="image.png" src="https://files.readme.io/60c7c66fb50312ee4fcd3e1c772b6880f32e6ed507aed13d87af921805da4b97-postman2.png" />

### Step 3: Send the Request

Add your request body (if required) and click **Send**.

***

### Using cURL

```bash
curl -X POST https://data.veridion.com/match/v5/companies \
  -H "Authorization: Bearer your_access_token" \
  -H "Content-Type: application/json" \
  -d '{
    "your": "request body"
  }'

```

Replace `your_access_token` with the token you obtained from the authentication step.

***

## Error Handling

| HTTP Status        | Meaning                  | Resolution                                                                                                                      |
| ------------------ | ------------------------ | ------------------------------------------------------------------------------------------------------------------------------- |
| `401 Unauthorized` | Invalid or expired token | Generate a new access token                                                                                                     |
| `403 Forbidden`    | Insufficient permissions | Verify your account has access to the requested resource. Contact your Veridion representative if you believe this is an error. |

***

## Troubleshooting

If you are unable to obtain a token, check the following:

* **Invalid credentials:** Verify that your `client_id` and `client_secret` are correct
* **Invalid scope:** Ensure you are requesting the `api:use` scope
* **Invalid URL:** Confirm you are using `https://auth.veridion.com/oauth2/token`

If you are receiving errors when calling the API:

* **401 error:** Your token may have expired. Generate a new token.
* **403 error:** Your account may not have permission to access the requested resource. Contact your Veridion representative.

***

## Best Practices

* **Cache your tokens:** Access tokens are valid for 60 minutes. Cache and reuse them rather than requesting a new token for every API call.
* **Handle expiration gracefully:** Implement token refresh logic in your application to automatically obtain a new token before or when the current one expires.
* **Keep credentials secure:** Never expose your `client_secret` in client-side code, logs, or version control.