1. API Guides
🇺🇸 English
  • 🇺🇸 English
  • 🇪🇸 Español
  • 🇨🇳 中文(简体)
  • Cobre Intro
    • Welcome
    • Get started
    • Connect Cobre's Documentation to AI
    • Products
      • Local Payments
        • Local Payments with Cobre
        • Payouts
          • Colombia
            • Money Movements with Bre-B
            • Money Movements with Cobre Fast Pay
          • Mexico
            • Money Movements with CLABEs and SPEI Cards
          • United States
            • Money Movements with Fedwire
          • Multi-region
            • Money Movements Scheduler
        • Payins
          • Colombia
            • Checkout
            • Request to Pay (R2P) Colombia
            • Direct Debit with Nequi
            • Static Bre-B Keys
            • Transfer-In
          • México
            • Request to Pay (R2P) Mexico
            • CLABE-backed Virtual Balances Accounts (Cobre Balances)
            • Virtual CLABEs
          • United States
            • Fedwire Payins at Cobre
        • Other features
          • Bulk Money Movements
          • Enabling Approval Workflows (Maker–Checker)
          • Named Accounts in Mexico
      • Cross Border Payments
        • Cross Border Payments with Cobre
      • Stablecoins
        • Stablecoins with Cobre
        • Global Payins in Stablecoins
        • Global Payouts in Stablecoins
        • Stablecoin Funding (On-Ramp & Off-Ramp)
        • StableFX
        • COPco & Rewards
      • Connect
        • Connect bank accounts with Cobre
    • Other features
      • Account Verification
      • Notifications and subscriptions
      • Security at Cobre
      • Performance and throughput
      • Reconciliation at Cobre
    • Using Cobre
      • Bre-B Payouts with Payment Instruments of Your Ecosystem
      • Cobre for Lenders
      • Integrating Cobre from ERPs
  • Portal
    • Introduction & Quick Start
    • Authentication in Portal
    • Troubleshooting & Support
    • Movements
      • Approval Process (Maker-Checker)
      • Local Money Movement
      • Unitary Payment Initiation
      • Bulk Money Movement Initiation
      • Cross-Border Money Movements
      • Scheduler
      • Payment Links
    • Transactions
      • Transactions
    • Accounts
      • Account and Balance Management
      • Account References
        • Virtual CLABEs
        • Transfer Accounts (Transfer-In)
    • Counterparties
      • Counterparties
    • Reports
      • Reports & Reconciliation
    • Settings
      • Users and Roles Management
      • Security and Control
    • Developers
      • Subscription management
  • Developers
    • API Guides
      • Quick Start
      • Authentication
      • Cobre Balances
        • Managing Virtual Balance Accounts (Cobre Balances)
        • Account Linkeage
        • Named Accounts (MX)
      • Connect Accounts
        • Managing Connect Accounts
      • Counterparties
        • Managing Counterparties
      • Local Payments
        • Money Movement
        • Payouts
          • Colombia
            • Fast Pay & ACH
            • Bre-B
          • Mexico
            • SPEI
          • United States
            • Fedwire Payouts
          • Cross-Region
            • Money Movements Approval
            • Bulk Money Movements
            • Bulk Money Movements Approval
            • Money Movement Scheduler
        • Payins
          • Colombia
            • Cobre Keys with Bre-B
            • Checkout
            • Direct Link
            • Direct Debit
            • Transfer-In
            • Processing Refunds in Colombia
          • Mexico
            • Account Reference – Virtual CLABEs
            • Direct Link
            • Processing Refunds in Mexico
          • United States
            • Fedwire Payins
      • Cross Border Payments
        • Cross Border Payments
        • Create Fx Quotes
        • Create a Cross Boder Money Movement
        • Fund your global Cobre Balance
        • Create a Generic Money Movement
      • Cross Features
        • Account Verification
        • Reports
        • Report Scheduler
        • Evidence API
        • Notifications & Subscriptions
        • FX Alerts
      • Reconciliation
        • Payouts Reconciliation
        • Payins Reconciliation in Colombia
        • Payins Reconciliation in México
        • Opening and Closing Balance Reconciliation
        • Account Linkage Reconciliation
      • Testing
        • Testing Cases
        • Testing PSE and Bancolombia
        • General Testing
      • Certification
        • Certification Process
        • Questionnaire
      • Stablecoins
        • Stablecoins
        • Managing Stablecoin Balances & Wallets
        • Stablecoin Payins
        • Stablecoin Payouts
        • Stablecoin Funding (On/Off-Ramp)
        • StableFX
        • COPco Rewards
        • Global payouts in stable
      • Others
        • Managing API and Product Changes
        • Security Considerations
        • Performance Guidelines: Rate and Burst Limit Considerations
    • API Explorer
      • Authentication
        • Authentication
      • Accounts
        • Create or Connect an Account
        • Obtain all Accounts
        • Obtain one Account
        • Update an Account
        • Close a Cobre Balance
        • Obtain an Account Transactions
        • Obtain an Account Transaction
        • Obtain all Transactions
        • Obtain one Transaction
        • Obtain Account Daily Balance History
        • Assign or Change Primary Account
        • Unlinking Primary Account
      • Account Verifications
        • Create an Account Verification
        • Obtain one Account Verification
        • Obtain all Account Verifications
      • Account References
        • Create an Account Reference
        • List one Account Reference
        • List all Account References
        • Delete an Account Reference
        • Generate a Certificate for your Account Reference
      • Cobre Keys
        • Create a Key
        • Obtain all Keys
        • Obtain one Key
        • Cancel a Key
        • Block or Reactivate Keys
      • Counterparties
        • Account Debit Registration
          • Register a Counterparty for Direct Debit
          • Obtain all Registrations
          • Obtain one Registration
        • Create a Counterparty
        • Obtain one Counterparty
        • Obtain all Counterparties
        • Delete a Counterparty
      • Money Movements
        • Create a Money Movement
        • Obtain one Money Movement
        • Obtain all Money Movements
        • Return a Money Movement
      • Money Movement Approvals
        • Approve a Money Movement
        • List all Money Movement Approvals
      • Money Movement Scheduler
        • Create a Money Movement Scheduler
        • List all Money Movement Schedulers
        • Cancel an Active Scheduler
      • Bulk Money Movement
        • Create a Bulk Money Movement
        • List all Bulk Money Movements
        • List one Bulk Money Movement
      • Bulk Money Movement Approvals
        • Bulk Money Movements Decision
      • Cross Border
        • Create a FX Quote
        • Obtain one FX Quote
        • Obtain all the FX Quotes
        • Create a Cross Border Money Movement
        • Obtain one Cross Border Money Movement
        • Obtain all the Cross Border Money Movements
      • Checkout
        • Create a Checkout
        • Obtain one Checkout
        • Obtain all Checkouts
        • Desactivate a Checkout
      • Evidence
        • Evidence Requests
          • Obtain Evidence Request
          • Search Evidence Requests
        • Evidence Documents
          • Generate Upload Links
          • Generate Download Link
        • Evidence Information
          • Submit Evidence Information
      • Reports
        • Create a Report
        • Obtain all Reports
        • Generate Download Link for Selected Reports
        • Create a Cobre Balance Statement
      • Report Scheduler
        • Create a Report Scheduler
        • Obtain all Reports Schedulers
        • Delete a Report Scheduler
      • Notifications & Subscriptions
        • Subscribe to Events
        • Obtain all Subscriptions
        • Delete a Subscription
        • List all Available Events
      • Alerts
        • Create Alert
        • Obtain All Alerts
        • Obtain One Alert
        • Deactivate An Alert
      • Subclients
        • Create a Subclient
        • Obtain all Subclients
        • Obtain one Subclient
    • Development Toolkit
      • How to integrate with Cobre
      • Build with AI
      • Create a Solution Design with AI
      • Generate Code with MCP
      • Explore API Workflow Examples
    • Platform Catalogs
      • Mexican Bank Codes
      • Error Dictionary
      • Transaction Types
      • Account Providers
      • Money Movement Statuses
      • Colombian Bank Codes
    • Testing APIs
      • Create a Transaction Adjustment
      • Change a Money Movement Status
      • Transaction Adjustment (QA)
      • Change Money Movement Status (QA)
    • Reports Layout
      • Money Movements Layout
        • All Money Movements (CSV)
        • All Money Movements (JSON)
        • SPEI Money Movements (CSV)
        • LEGACY Money Movements (CSV)
      • Transactions Layout
        • All Transactions (CSV)
        • All Transactions (JSON)
        • Virtual Balance Account (Cobre Balance) Statement (PDF)
      • Counterparties Layout
        • All Counterparties (CSV)
      • Multicash Layout
        • Multicash Header (TXT)
        • Multicash Detail (TXT)
    • Notifications Layout
      • Account Events
        • Account Balance Credit
        • Account Balance Debit
      • Cobre Keys
        • Cobre Keys
      • Counterparties
        • Counterparties
        • Direct Debit Registration
      • Money Movement
        • Money Movement
      • Bulk Money Movement
        • Bulk Money Movement
      • Cross Border Money Movement
        • Cross Border Money Movement
      • Evidence Requests
        • Evidence Requests
      • Reports
        • Reports
      • Alerts
        • FX Alerts
      • Account References
        • Self-custodian wallet
        • Transfer-in
      • Subclients
        • Subclients
  • Schemas
    • Counterparties
      • Colombia
        • PayOut
          • Counterparty | Create Metadata Type Cobre Balance (CO)
          • Counterparty | Response Metadata Type Cobre Balance (CO)
          • Counterparty | Create Metadata Type Breb Key (CO)
          • Counterparty | Response Metadata Type Breb Key (CO)
          • Counterparty | Create Metadata Type QR (CO)
          • Counterparty | Response Metadata Type QR (CO)
          • Counterparty | Create Metadata Type CC (CO)
          • Counterparty | Response Metadata Type CC (CO)
          • Counterparty | Create Metadata Type CH (CO)
          • Counterparty | Response Metadata Type CH (CO)
          • Counterparty | Create Metadata Type DP (CO)
          • Counterparty | Response Metadata Type DP (CO)
        • PayIn
          • Counterparty | Response Metadata Type r2p (CO)
          • Counterparty | Create Metadata Type r2p (CO)
          • Counterparty | Create Metadata Type r2p Breb (CO)
          • Counterparty | Response Metadata Type r2p Breb (CO)
        • Secondary Counterparty
          • Secondary Counterparty Create Request
          • Secondary Counterparty Create Response (CO)
          • Secondary Counterparty Create Metadata Type NP (CO)
          • Secondary Counterparty Response Metadata Type NP (CO)
          • Secondary Counterparty Request Metadata Type LE
          • Secondary Counterparty Response Metadata Type LE (CO)
        • Direct Debit
          • Direct Debit Registration | Create
          • Direct Debit Registration | Response
          • Direct Debit Registration | List All Items
        • Counterparty | Create Request (CO)
        • Counterparty | Create Response (CO)
      • Mexico
        • PayOut
          • Counterparty | Create Metadata Type Clabe (MX)
          • Counterparty | Response Metadata Type Clabe (MX)
          • Counterparty | Create Metadata Type SPEI Card (MX)
          • Counterparty | Response Metadata Type SPEI Card (MX)
        • PayIn
          • Counterparty | Create Metadata Type r2p (MX)
          • Counterparty | Response Metadata Type r2p (MX)
        • Counterparty | Create Response (MX)
        • Counterparty | Create Request (MX)
        • Counterparty | Money Movement Return (MX)
      • Global
        • Counterparty | Global CP Request
        • Counterparty | Global Deposit NP request
        • Counterparty | Global Deposit NP response
        • Counterparty | Global Deposit LE request
        • Counterparty | Global Deposit LE response
        • Counterparty | Global CP Response
      • USA
        • Counterparty | Create Request (USA)
        • Counterparty | Create Response (USA)
        • Request Medatata Business
        • Response Medatata Business
        • Request Medatata Individual
        • Response Medatata Individual
        • Counterparty | Create Request (USA)
        • Counterparty | Create Response (USA)
      • Generic
        • Counterparty | Generic CP Request
        • Counterparty | Generic CP Response
        • Payment Information | SWIFT
        • Payment Information | SEPA
        • Payment Information | CIPS
        • Payment Information | Fedwire
      • Counterparty | List All Items
    • Authentication
      • Authentication | Request
      • Authentication | Response
    • Transactions
      • Global
        • Transaction | Debit Cross Border
        • Transaction | Credit Cross Border
      • Colombia
        • Debit
          • Transaction | Debit FI (CO) (col_debit)
          • Transaction | Debit Cobre Balance (CO)
          • Transaction | Debit Breb (CO) (breb_debit)
        • Credit
          • Transaction | Credit Direct Debit (CO) (dd_credit)
          • Transaction | Rejected Breb (breb_rejected)
          • Transaction | Credit Top Up (CO) (col_top_up_credit)
          • Transaction | Credit FI (CO) (col_credit)
          • Transaction | Credit Cobre Balance (CO) (col_cb_credit)
          • Transaction | Credit r2p (r2p_credit)
          • Transaction | Credit Breb (CO) (breb_credit)
          • Transaction | Credit r2p Breb (CO) (r2p_breb_credit)
        • Transaction | Connect Obtain (CO)
        • Transaction | Cobre Balance Obtain (CO)
      • Mexico
        • Debit
          • Transaction | Debit FI (MX) (mex_debit)
          • Transaction | Debit SPEI (MX) (spei_debit)
          • Transaction | Debit Internal SPEI (MX)
        • Credit
          • Transaction | Credit FI (MX)
          • Transaction | Credit SPEI (MX)
          • Transaction | Credit Internal SPEI (MX)
        • Transaction | Connect Obtain (MX)
        • Transaction | Return SPEI (MX)
        • Transaction | Cobre Balance Obtain (MX)
      • Transactions | Connect List All Items
      • Transaction | Debit Misc
      • Transaction | Credit Misc
      • Transaction | Adjustment Debit
      • Transaction | Adjustment Credit
      • Transactions | Cobre Balance List All Items
      • Transaction Metadata | global_credit
      • Transaction Metadata | global_debit
      • Transaction Metadata | stable_payout_debit
      • Transaction Metadata | onramp_credit
      • Transaction Metadata | onramp_debit
      • Transaction Metadata | offramp_credit
      • Transaction Metadata | offramp_debit
      • Transaction Metadata | reward_credit
      • Transaction Metadata | cbmm_debit (StableFX)
      • Transaction Metadata | cbmm_credit (StableFX)
      • Transaction | Cobre Balance Obtain (Global/Stable)
    • Cobre Keys
      • Colombia
        • Cobre Key | Create Request
        • Cobre Key | Create Response
        • Cobre Key | Obtain Response
        • Cobre Key | Reactive Request
    • Money Movements
      • Approvals
        • Money Movement Approvals | Create Request
        • Money Movement Approvals | Create Response
        • Money Movement Approvals | List All Items
      • Mexico
        • PayOut
          • Money Movement | Create Metadata Type SPEI
          • Money Movement | Response Metadata Type SPEI
        • Return
          • Money Movement Return | Create Request
          • Money Movement Return | Create Response
          • Money Movement Return | Response Medatada Type SPEI
        • PayIn
          • Money Movement Direct Link | Create Metadata Rail r2p SPEI
          • Money Movement Direct Link | Response Metadata Rail r2p SPEI
      • Colombia
        • PayOut
          • Money Movement | Create Metadata Type Fast Pay
          • Money Movement | Response Metadata Type Bre-B
          • Money Movement | Create Metadata Type Bre-B
          • Money Movement | Response Metadata Type Fast Pay
          • Money Movement | Create Metadata Type ACH
          • Money Movement | Response Metadata Type ACH
          • Money Movement | Response Metadata Type Bre-B
          • Money Movement | Response Metadata Type Bre-B Split
        • PayIn
          • Money Movement Direct Link | Create Metadata Rail r2p
          • Money Movement Direct Link | Response Metadata Rail PSE
          • Money Movement Direct Link | Response Metadata Rail Bancolombia
          • Money Movement Direct Link | Response Metadata Rail Nequi
          • Money Movement Direct Link | Create Metadata Rail r2p Breb
          • Money Movement Direct Link | Response Metadata Rail r2p Breb
        • Direct Debit
          • Money Movement Direct Debit | Create Metadata
          • Money Movement Direct Debit | Response Metadata
      • Global
        • Payout in stable
          • Money Movement | Create Metadata Type Global (stable)
          • Money Movement | Response Metadata Type Global (stable)
          • Money Movement | Create Metadata Type Stable Payout
          • Money Movement | Response Metadata Type Stable Payout
      • United States
        • PayOut
          • Money Movement | Create Metadata Type Fedwire
          • Money Movement | Response Metadata Type Fedwire
        • PayOuts
      • Generic
        • Money Movement | Create Metadata Type Generic
        • Money Movement | Response Metadata Type Generic
      • Money Movement | List All Items
      • Money Movement | Create Metadata Type On-Ramp / Off-Ramp
      • Money Movement | Create Response
      • Money Movement | Response Metadata Type On-Ramp / Off-Ramp
    • Accounts
      • Account Verification
        • Mexico
          • Account Verification Create Metadata Type mex_acc_details_1
          • Account Verification Response Metadata Type mex_acc_details_1
          • Account Verification Create Request
          • Account Verification Create Metadata Type mex_acc_ownership_1
          • Account Verification Response Metadata Type mex_acc_ownership_1
        • Colombia
          • Account Verification Response Metadata Type col_key_details_1
          • Account Verification Create Metadata Type col_key_details_1
          • Account Verification Create Metadata Type col_key_ownership_1
          • Account Verification Response Metadata Type col_key_ownership_1
          • Account Verificacion Response Metadata Type col__key_ownership_2
          • Account Verification Create Metadata Type col_key_ownership_2
        • Account Verification Create Response
        • Account Verifications List All Items
      • Account References
        • Account References Request
        • Account Reference Response
        • List all account references
        • Account Reference Certificate Generation Response
        • Account References Request (Self-Custodian Wallet)
        • Account Reference Response (Self-Custodian Wallet)
      • Daily Balance
        • Daily Balance Historiy List All Items
        • Daily Balance Obtain Response
      • Cobre Balances and Connect Accounts
        • Mexico
          • Cobre Balance | Create Metadata (MX)
          • Cobre Balance | Create Response (MX)
          • Connect Account | Create Metadata (MX)
          • Connect Account | Response Metadata (MX)
        • Colombia
          • Cobre Balance | Create Metadata (CO)
          • Connect Account | Create Metadata (CO)
          • Connect Account | Response Metadata (CO)
          • Cobre Balance | Create Response (CO)
        • Global
          • Cobre Balance | Create Metadata (Global)
          • Cobre Balance | Create Response (Global)
          • Cobre Balance | Create Metadata (Stable)
          • Cobre Balance | Create Response (Stable)
        • USA
          • Cobre Balance | Create Metadata (USA)
          • Cobre Balance | Create Response (USA)
        • Cobre Balance | Create Request
        • Connect Account | Create Request
        • Accounts | List All Items
        • Account | Update Request
    • Bulk Money Movement
      • Bulk Money Movement | Obtain Response
      • Bulk Money Movement Decision | Create Request
      • Bulk Money Movements | List All Items
    • Money Movement Scheduler
      • Money Movement Scheduler | Create Request
      • Money Movement Scheduler | Create Response
      • Money Movement Scheduler | List All Items
    • Checkout
      • Colombia
        • Checkout | Create Request
        • Checkout | Create Response
        • Checkout | List All Items
        • Checkout | Delete
    • Notifications
      • Subscription | Create Response
      • Subscription | Create Request
      • Subscription | List All Items
      • Subscribable Events | List All Items
      • Subscribable Events | Metadata
    • Evidence Request
      • Schemas
        • Error
        • Evidence Request
        • Document Type
        • Evidence Id
        • Upload Intent
        • Evidence Request Id
        • Evidence Request Status
        • Information Type
        • Information
        • Evidence
        • Information Status
        • Document
        • Document Status
        • Headers
      • RequestBodies
        • Upload Intent Request
    • Cross Border
      • Cross Border Money Movement
        • Cross Border Money Movement Create Request
        • Cross Border Money Movement Create Response
        • CBMM Obtain Response | Static Quote
        • CBMM Obtain Response | Rolling Quote
        • Cross Border Money Movements List All Items
      • FX Quote
        • FX Rolling Quote
          • FX Quote Static | Create Response
          • FX Quote Static | Cross Border Response
        • FX Static Quote
          • FX Quote Rolling | Create Response
          • FX Quote Rolling | Cross Border Response
        • FX Quote | List All Items
        • FX Quote | Metadata Quote Tiers
        • FX Quote | Metadata Penalization Tier
        • FX Quote | Metadata Fees Breakdown
        • FX Quote | Create Request
    • Reports
      • Download
        • Report Download Create Request
        • Report Download Create Response
      • Reports Create Request
      • Reports Create Response
      • Reports Create Metadata
      • Reports List All Items
      • Cobre Balance Statement Request
      • Cobre Balance Statement Response
    • Error Model
      • Error Model
    • Report Scheduler
      • Report Schedulers | Create Request
      • Report Schedulers | Delete Response
    • Alerts
      • Create Alert
      • Alert Object
      • List All Alerts
      • Alert | Metadata Type fx_rate
    • Subclients
      • Subclients | Create Request (MX)
      • Subclients | Create Response (MX)
  1. API Guides

Authentication

Cobre's Authentication API enables secure, frictionless access to the Cobre Move Money platform. Authenticate with a user_id and secret obtained from the Cobre Portal to receive a short-lived JSON Web Token (JWT) for all subsequent API calls.

Cobre Authentication API Guide#

The Cobre Authentication API facilitates secure interactions within the Cobre Money Movement platform. Follow this step-by-step guide to authenticate and use the platform services effectively.
1
Obtain API Credentials
Before you can authenticate, you need to obtain the necessary API credentials: a user_id and a secret. These credentials are provided within the Cobre ecosystem, ensuring a secure and straightforward way to access the platform.
2
Authenticate into the Platform
With your API credentials in hand, use them to authenticate into the platform. Send a request to the Authentication API endpoint, including your user_id and secret. Upon successful authentication, the API returns a JSON Web Token (JWT).
Authentication request example:
POST /auth
Content-Type: application/json

{
  "user_id": "your_user_id",
  "secret": "your_secret"
}
Authentication response example:
{
    "access_token": "eyJhbGciOiJSUzI1...",
    "type": "Bearer",
    "expiration_time": 1200
}
3
Start moving money!
With the JWT token in hand, you will be able to initiate all your money movement operations!

Login cache and token lifecycle#

Cobre caches login tokens server-side. When you call the Authentication endpoint with the same credentials, Cobre checks the cache before issuing a new token:
Cache hit — returns the cached token; no new JWT is generated.
Cache miss — generates a new token and stores it in the cache.
The cache TTL is 90% of the token lifetime. This creates a 10% safety buffer where the JWT is still valid but the cache has already expired, so the next login call always fetches a fresh token rather than serving one close to expiry.
Production token lifetime is currently 1 200 s (20 min). This value may change; all proportions below hold for any expiration_time.
cache-timeline.gif

What expiration_time means in each scenario#

Scenarioexpiration_time in the response
Cache miss (first call, or after cache TTL expires)Full token lifetime (e.g. 1 200 s)
Cache hit (0 < T < cache TTL)Remaining cache TTL — not the remaining JWT lifetime
On a cache hit, treat expiration_time as the remaining time until you should refresh — not as the JWT's absolute expiry. Example: at T + 1 min, you may receive 1 020 s even though the underlying JWT was issued earlier.
ParameterValue (20-min token example)
Token lifetime1 200 s (20 min)
Cache TTL (90%)1 080 s (18 min)
10% safety buffer120 s (2 min) — token valid, cache gone
Recommended client refresh (95%)1 140 s (19 min)

Token management best practices#

Cobre APIs use short-lived access tokens, so your integration must handle token refresh in a controlled way:
Do not request a new token on every API call. This is inefficient and may cause you to be blocked due to rate limiting.
Cache the token, reuse it, and refresh it only when it is close to expiration.
Implement a single token manager that all Cobre API requests share.
This provides:
Lower latency (fewer auth calls)
More stable throughput
Cleaner error handling and observability
Better resilience under load

Recommendations#

1.
Cache the token client-side and reuse it until expiration_time elapses — never call /v1/auth on every request.
2.
Refresh at 95% of expiration_time (1 140 s / 19 min for 20-min tokens). The server cache expires at 90% (18 min), so calling at 95% always falls after the cache has already expired — guaranteeing a fresh token.
3.
Share one token per credential set across workers — parallel calls benefit from the same cache entry.
Store tokens in memory when possible (fastest). If you run multiple instances, consider a shared cache (Redis, Memcached) so all replicas reuse the same token.

Reference implementation (language-agnostic pseudocode)#

Use this logic before every request to Cobre:
function getValidToken():
  refresh_at = cached_expires_at - (0.05 * cached_expiration_time)

  if cached_token exists AND now < refresh_at:
      return cached_token

  lock(token_refresh_lock):
      # Double-check after acquiring lock
      if cached_token exists AND now < refresh_at:
          return cached_token

      response = requestNewToken()
      cached_token = response.access_token
      cached_expiration_time = response.expiration_time
      cached_expires_at = now + response.expiration_time
      return cached_token
If your system makes parallel requests, use a lock or mutex to ensure only one refresh occurs at a time and all other requests wait for it. This avoids token storms — multiple simultaneous token refreshes under load.

Handling a 401 response#

A 401 on any Cobre API endpoint means the Authorization: Bearer <access_token> header is missing, malformed, or the token has expired or is otherwise no longer valid — distinct from 403 (valid token, insufficient permission on that resource).
A 401 should be rare if you follow the refresh-at-95% pattern above. Treat it as a fallback safety net, not your primary token-management strategy.
Recommended handling:
1.
On 401, call POST /auth again with your user_id/secret to obtain a new token.
2.
Retry the original request once with the new token.
3.
If the retry also returns 401, stop retrying — this signals invalid credentials (not an expired token) and should surface as a hard failure for someone to check the user_id/secret.
For non-idempotent requests (e.g. creating a Money Movement), do not retry-after-refresh without an idempotency key. If the original request was already processed by Cobre before the response reached you, a blind retry can create a duplicate. Reuse the same idempotency key on the retry.
response = call(endpoint, token)
if response.status == 401:
    token = requestNewToken()
    response = call(endpoint, token, idempotency_key=same_key)
    if response.status == 401:
        raise AuthenticationError("Invalid credentials")

Allowed Actions on Authentication#

🔑 Authenticate
Description: Exchange your user_id and secret for a short-lived Bearer token.
What to expect after the action: A JWT with access_token, type, and expiration_time.
📘 Learn more:
🔗 Authentication

How to Get Started#

Before you begin, we recommend having clarity on the preliminary steps required before using this solution.
1
Create your API credentials from the Portal
Access the Portal and find the Developers section at the bottom of the left side menu.
Once in the Developers section, click on the API credentials tab, then in + Create Credential.
A new window will pop-up. Assign an alias and select the role to create your API credential with the necessary access.
Once the credential is generated, make sure you store it in a safe place since it won't be possible to get it again.

What to expect after using this API#

1
Use the JWT on all Cobre API calls
Pass the token in the Authorization: Bearer <access_token> header on every subsequent request to Cobre APIs.
2
Cache and refresh based on expiration_time
Store the token and its expiration timestamp. Reuse the cached token until you reach the 95% refresh point described in Token management best practices — do not request a new token on every business API call.
3
Continue to other API Guides
See next sections to learn more about Cobre APIs and start integrating money movement flows.

Get to know our Authentication API technical documentation:
Authentication API
Get Authentication tokens to start using Cobre APIs
Modified at 2026-08-20 21:18:05
Previous
Quick Start
Next
Managing Virtual Balance Accounts (Cobre Balances)
Built with