> ## Documentation Index
> Fetch the complete documentation index at: https://developers.marko.fr/llms.txt
> Use this file to discover all available pages before exploring further.

# Obtenir un bearer court

> Echange une cle API brute contre un bearer MARKO court. La signature HMAC-SHA256 est calculee avec la cle API brute sur le message canonique `MARKO-EXTERNAL-API-TOKEN-V1\n{key_id}\n{timestamp}\n{nonce}`. Utilisez ensuite `Authorization: Bearer YOUR_BEARER_HERE` sur les endpoints metier.

Cette route échange la signature HMAC contre un bearer; aucun bearer préalable n'est requis. [Authentification](/authentication).



## OpenAPI

````yaml /openapi.json post /auth/token
openapi: 3.1.0
info:
  title: MARKO External Partner API
  version: v1
  description: >-
    Stable external API contract for the live environment.


    Authentication flow for partner integrations:

    1. Generate an API key from the MARKO entity admin API section.

    2. Keep the raw API secret server-side and use it only to sign `POST
    /v1/auth/token`.

    3. Build the canonical message
    `MARKO-EXTERNAL-API-TOKEN-V1\n{key_id}\n{timestamp}\n{nonce}`.

    4. Sign that message with HMAC-SHA256 and send the hex signature with
    `key_id`, `timestamp` and `nonce`.

    5. Use the returned short-lived bearer on business endpoints as
    `Authorization: Bearer <access_token>`.

    The raw API secret must never be sent on business endpoints.


    This public contract intentionally excludes beta endpoints.


    Référence enrichie pour les développeurs et les assistants IA. Exemples
    synthétiques; les champs sont extraits des modèles et sérialiseurs de la
    version indiquée dans x-documentation-provenance.
servers:
  - url: https://partner-api.marko.fr/v1
security:
  - BearerAuth: []
tags:
  - name: auth
    x-group: Authentification
  - name: entity
    x-group: Entité
  - name: portfolio
    x-group: Portefeuille
  - name: deals
    x-group: Deals
  - name: fonds
    x-group: Fonds
  - name: spvs
    x-group: SPV
  - name: operations
    x-group: Opérations
  - name: taxonomies
    x-group: Taxonomies
  - name: import-jobs
    x-group: Imports par lot
  - name: comments
    x-group: Commentaires
  - name: documents
    x-group: Documents
  - name: users
    x-group: Utilisateurs
  - name: settings
    x-group: Paramètres
  - name: rcci
    x-group: Conformité RCCI
  - name: field-definitions
    x-group: Champs métier
  - name: search
    x-group: Recherche
  - name: operateurs
    x-group: Opérateurs
  - name: alerts
    x-group: Alertes
  - name: notifications
    x-group: Notifications
  - name: calendar
    x-group: Calendrier
  - name: enrichment
    x-group: Enrichissement SIREN
  - name: reports
    x-group: Exports
  - name: reporting
    x-group: Templates de reporting
  - name: workflows
    x-group: Workflows et extraction IA
  - name: tasks
    x-group: Tâches
externalDocs:
  description: Download the matching Postman collection.
  url: /v1/postman.json
paths:
  /auth/token:
    post:
      tags:
        - auth
      summary: Obtenir un bearer court
      description: >-
        Echange une cle API brute contre un bearer MARKO court. La signature
        HMAC-SHA256 est calculee avec la cle API brute sur le message canonique
        `MARKO-EXTERNAL-API-TOKEN-V1\n{key_id}\n{timestamp}\n{nonce}`. Utilisez
        ensuite `Authorization: Bearer YOUR_BEARER_HERE` sur les endpoints
        metier.


        Cette route échange la signature HMAC contre un bearer; aucun bearer
        préalable n'est requis. [Authentification](/authentication).
      operationId: auth_token_exchange
      parameters:
        - in: header
          name: X-Request-ID
          required: false
          description: >-
            Partner-generated correlation identifier echoed in logs and error
            payloads.
          schema:
            type: string
          example: marko-auth-token-exchange
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ExternalAPIBearerTokenExchangeRequest'
            example:
              key_id: examplekey01
              timestamp: 1776926400
              nonce: UNIQUE_NONCE_16_CHARS
              signature: '0000000000000000000000000000000000000000000000000000000000000000'
        required: true
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ExternalAPIBearerTokenResponse'
              example:
                access_token: YOUR_BEARER_HERE
                token_type: Bearer
                expires_in: 900
                issued_at: '2026-04-23T10:00:00Z'
                expires_at: '2026-04-23T10:15:00Z'
                key_id: YOUR_PUBLIC_KEY_ID
                environment: live
                entity_slug: clubfunding
        '401':
          description: Authentication required
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemDetails'
              example:
                type: about:blank
                title: Unauthorized
                status: 401
                detail: A valid bearer token is required.
                request_id: req_example_partner_call
        '403':
          description: Scope, route or IP restriction
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemDetails'
              example:
                type: about:blank
                title: Forbidden
                status: 403
                detail: The API key does not allow this operation.
                request_id: req_example_partner_call
        '422':
          description: Validation failed
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemDetails'
              example:
                type: about:blank
                title: Unprocessable Content
                status: 422
                detail: The request payload or parameters are invalid.
                request_id: req_example_partner_call
        '429':
          description: Rate limit or progressive ban
          headers:
            Retry-After:
              description: Cooldown in seconds before retrying the request.
              schema:
                type: string
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemDetails'
              example:
                type: about:blank
                title: Too Many Requests
                status: 429
                detail: The request rate limit was exceeded.
                request_id: req_example_partner_call
        '500':
          description: Unexpected server error
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ProblemDetails'
              example:
                type: about:blank
                title: Internal Server Error
                status: 500
                detail: An unexpected server error occurred.
                request_id: req_example_partner_call
      deprecated: false
      security: []
      x-codeSamples:
        - lang: Shell
          label: cURL + OpenSSL
          source: >-
            api_key="YOUR_API_KEY"

            key_id="YOUR_PUBLIC_KEY_ID"

            timestamp="$(date +%s)"

            nonce="$(openssl rand -hex 16)"

            message="$(printf 'MARKO-EXTERNAL-API-TOKEN-V1\n%s\n%s\n%s'
            "$key_id" "$timestamp" "$nonce")"

            signature="$(printf "%s" "$message" | openssl dgst -sha256 -hmac
            "$api_key" -hex | awk '{print $2}')"


            curl -X POST "https://partner-api.marko.fr/v1/auth/token" \
              -H "Content-Type: application/json" \
              -H "X-Request-ID: marko-auth-token" \
              --data "$(printf '{"key_id":"%s","timestamp":%s,"nonce":"%s","signature":"%s"}' "$key_id" "$timestamp" "$nonce" "$signature")"
        - lang: Python
          label: Python HMAC
          source: >-
            import hashlib

            import hmac

            import secrets

            import time


            import requests


            api_key = "YOUR_API_KEY"

            key_id = "YOUR_PUBLIC_KEY_ID"

            timestamp = int(time.time())

            nonce = secrets.token_urlsafe(24)

            message =
            f"MARKO-EXTERNAL-API-TOKEN-V1\n{key_id}\n{timestamp}\n{nonce}"

            signature = hmac.new(api_key.encode(), message.encode(),
            hashlib.sha256).hexdigest()


            resp = requests.post(
                "https://partner-api.marko.fr/v1/auth/token",
                headers={"X-Request-ID": "marko-auth-token"},
                json={
                    "key_id": key_id,
                    "timestamp": timestamp,
                    "nonce": nonce,
                    "signature": signature,
                },
                timeout=30,
            )

            resp.raise_for_status()

            access_token = resp.json()["access_token"]
        - lang: TypeScript
          label: Node HMAC
          source: >-
            import { createHmac, randomBytes } from "node:crypto"


            const apiKey = "YOUR_API_KEY"

            const keyId = "YOUR_PUBLIC_KEY_ID"

            const timestamp = Math.floor(Date.now() / 1000)

            const nonce = randomBytes(24).toString("base64url")

            const message =
            `MARKO-EXTERNAL-API-TOKEN-V1\n${keyId}\n${timestamp}\n${nonce}`

            const signature = createHmac("sha256",
            apiKey).update(message).digest("hex")


            const response = await
            fetch("https://partner-api.marko.fr/v1/auth/token", {
              method: "POST",
              headers: {
                "Content-Type": "application/json",
                "X-Request-ID": "marko-auth-token",
              },
              body: JSON.stringify({
                key_id: keyId,
                timestamp,
                nonce,
                signature,
              }),
            })


            const { access_token: accessToken } = await response.json()
components:
  schemas:
    ExternalAPIBearerTokenExchangeRequest:
      properties:
        key_id:
          type: string
          maxLength: 24
          minLength: 4
          pattern: ^[a-z0-9]+$
          title: Key Id
          description: >-
            Identifiant public de la clé; utiliser la valeur réelle fournie par
            l'administrateur.
        timestamp:
          type: integer
          minimum: 0
          title: Timestamp
          description: Heure Unix en secondes de l'échange signé.
        nonce:
          type: string
          maxLength: 128
          minLength: 16
          pattern: ^[A-Za-z0-9_-]+$
          title: Nonce
          description: >-
            Valeur aléatoire unique pour cet échange; ne jamais réutiliser un
            nonce avec la même clé.
        signature:
          type: string
          maxLength: 64
          minLength: 64
          pattern: ^[A-Fa-f0-9]{64}$
          title: Signature
          description: >-
            HMAC-SHA256 hexadécimal du message canonique à quatre lignes; voir
            Authentification.
      type: object
      required:
        - key_id
        - timestamp
        - nonce
        - signature
      title: ExternalAPIBearerTokenExchangeRequest
    ExternalAPIBearerTokenResponse:
      properties:
        access_token:
          type: string
          title: Access Token
          description: Bearer de courte durée à utiliser dans Authorization.
        token_type:
          type: string
          title: Token Type
          default: Bearer
          description: 'Type de jeton retourné: Bearer.'
        expires_in:
          type: integer
          minimum: 1
          title: Expires In
          description: >-
            Durée du bearer en secondes; utilisez la valeur retournée plutôt
            qu'une durée fixe.
        issued_at:
          type: string
          format: date-time
          title: Issued At
          description: Date d'émission du bearer.
        expires_at:
          type: string
          format: date-time
          title: Expires At
          description: Date d'expiration du bearer.
        key_id:
          type: string
          title: Key Id
          description: >-
            Identifiant public de la clé; utiliser la valeur réelle fournie par
            l'administrateur.
        environment:
          type: string
          title: Environment
          description: >-
            Environnement de données associé à la clé; distinct de l'hôte
            d'infrastructure.
        entity_slug:
          type: string
          title: Entity Slug
          description: Entité à laquelle l'intégration est rattachée.
      type: object
      required:
        - access_token
        - expires_in
        - issued_at
        - expires_at
        - key_id
        - environment
        - entity_slug
      title: ExternalAPIBearerTokenResponse
    ProblemDetails:
      type: object
      required:
        - title
        - status
        - detail
      properties:
        type:
          type: string
          default: about:blank
          description: >-
            URI identifiant le type de problème; about:blank lorsque seul le
            statut HTTP le caractérise.
        title:
          type: string
          description: Titre affiché pour l'événement ou le problème.
        status:
          type: integer
          description: Statut HTTP de la réponse d'erreur.
        detail:
          type: string
          description: Informations détaillées sur le problème ou le dossier.
        request_id:
          type: string
          description: Identifiant de corrélation pour le diagnostic de la requête.
        scope:
          type: string
          description: Scope concerné par le refus d'accès, lorsqu'il est renseigné.
        route_id:
          type: string
          description: Identifiant de la route concernée par le problème.
        reason_code:
          type: string
          description: >-
            Code structuré du motif de refus; préférable au texte du message
            pour le diagnostic.
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: MARKO short-lived bearer
      description: >-
        Use the `access_token` returned by `POST /v1/auth/token`. Do not send
        the raw API secret on business endpoints.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.