Skip to main content
Authentication: none. This endpoint is rate limited; use only from a trusted merchant backend or portal server, never an untrusted client.

Request body

username is 3-64 characters. password is 12-256 characters.

Response

Send Authorization: Bearer <access_token> to all other portal endpoints. Portal credentials and JWTs never authorize KYC or payment creation; use the signed Partner API for those operations.