> ## Documentation Index
> Fetch the complete documentation index at: https://docs-api.kravata.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Obtain and refresh access tokens for the Kravata Business API.

Your API credentials are the **username** and **password** of your Kravata Business account. You create the account yourself in the Kravata Business portal.

## Get your credentials

| Environment | Register | Reset password |
| - | - | - |
| Test | [test-business.kravata.co/auth/register](https://test-business.kravata.co/auth/register) | [test-business.kravata.co/auth/resetpassword](https://test-business.kravata.co/auth/resetpassword) |
| Production | [business.kravata.co/auth/register](https://business.kravata.co/auth/register) | [business.kravata.co/auth/resetpassword](https://business.kravata.co/auth/resetpassword) |

<Steps>
  <Step title="Register your company">
    Fill in the registration form: person type, ID type and number (NIT with its verification digit for companies), business name, contact data, a **username** and a password. Accept the data policy and the terms and conditions, and complete the reCAPTCHA.
  </Step>

  <Step title="Wait for approval">
    Your account starts as pending. Kravata reviews your company and defines your business model. When it is approved, `status` and `complianceStatus` in [Get Client Info](/business/api-reference/authentication/get-client-info) become `approved`.
  </Step>

  <Step title="Use your credentials">
    Send your **username** (not your email) and your password to `POST /api/token`.
  </Step>
</Steps>

Passwords must have at least **14 characters**, including uppercase and lowercase letters, a number and a special character.

<Tip>
  **Forgot your password?** Open the reset page, enter your ID type and number, and type the 6-digit code that Kravata sends to your registered email. Then choose a new password.
</Tip>

## Tokens

You exchange your credentials for two JWT tokens:

| Token | Validity | Use |
| - | - | - |
| `access` | 5 minutes | Send it as `Authorization: Bearer <access>` in every request. |
| `refresh` | 24 hours | Exchange it for a new `access` token without sending your password again. |

## Get your tokens

```bash theme={null}
curl -X POST https://testapi.kravata.co/api/token \
  -H "Content-Type: application/json" \
  -d '{ "username": "YOUR_USERNAME", "password": "YOUR_PASSWORD" }'
```

```json theme={null}
{
  "refresh": "eyJhbGciOi...",
  "access": "eyJhbGciOi..."
}
```

## Refresh the access token

When the access token expires, request a new one with the refresh token:

```bash theme={null}
curl -X POST https://testapi.kravata.co/api/token/refresh \
  -H "Content-Type: application/json" \
  -d '{ "refresh": "YOUR_REFRESH_TOKEN" }'
```

```json theme={null}
{ "access": "eyJhbGciOi..." }
```

When the refresh token also expires, request a new pair with `POST /api/token`.

## Authenticate your requests

```bash theme={null}
curl https://testapi.kravata.co/api/infoClient \
  -H "Authorization: Bearer YOUR_ACCESS_TOKEN"
```

<Info>
  Most endpoints also require your `clientId`, in the path (`/api/accounts/{clientId}`) or as a query parameter (`/api/ramps?clientId=...`). Get it from [Get Client Info](/business/api-reference/authentication/get-client-info).
</Info>

<Warning>
  Call the API only from your backend. Never expose your password or tokens in a browser or mobile app.
</Warning>
