Authorization API

Authorization API offers a secure way for third-party clients or developers to access our API resources. This protocol supports Industry Standard OAuth 2.0 Authorization Framework in the following scenario:

  • Two-Legged OAuth: This is a machine-to-machine communication which is also known as client_credentials grant type.

In order to consume our APIs, you need to follow the Two-Legged OAuth authentication process by calling our identity provider /token endpoint.

Step 1: To obtain an access token, use client_credentials as the grant_type in your HTTP POST call.

$ curl -i -H 'Content-Type: application/x-www-form-urlencoded' -X POST https://ewbpoc.okta.com/oauth2/ausdaetdg9zY8EZuI2p6/v1/token' -d 'grant_type=client_credentials&client_id=<client_id>&client_secret=<client_secret>'

Step 2: Once the OAuth authentication is succeeded, a valid access token will be returned.

{

"access_token":"eyJz93a...k4laUWw",

"token_type":"Bearer",

"expires_in":86400

}

Step 3: You need to include that access token in the authorization header of every http request to the protected API endpoints.

Example: Authorization: Bearer eyJhb…………...

HOST URLs

Use the following URL to access the Token endpoint of East West Bank’s Authorization API

https://ewbpoc.okta.com/oauth2/ausdaetdg9zY8EZuI2p6/v1/token

East West Bank, compass logo, and East West Bank with compass logo are separately registered trademarks of East West Bank in the United States and other countries.  ©2006 - 2020, East West Bank. All Rights Reserved. NMLSR ID 469761
Investment products: Are Not FDIC Insured  |  Are Not Bank Guaranteed  |  May Lose Value  |  Are Not Insured by Any Federal Government Agency  |  Are Not Deposits

Picture