Authorization in the Back Office

Authenticate server-to-server requests against the Back Office API.

For admins

The B2COPY API uses bearer-token authorization. Call the sign-in method below to get an access/refresh token pair, then include the access token in the Authorization: Bearer <token> header of every subsequent request.

Prerequisite

To obtain tokens you must already be registered in the Back Office and have credentials to access it.

Endpoint

POST [host]/api/v2/signin

Request Body

NameTypeRequiredDescription
emailstringYesThe email address used to access the Back Office.
passwordstringYesThe password used to access the Back Office.
curl --location --request POST 'https://host.name/api/v2/signin' \
--data-raw '{
  "email": "username@example.com",
  "password": "Secret123"
}'

Response

The response returns a pair of access and refresh tokens, each with a token string and createdAt / expiresAt timestamps.

{
  "2faRequired": false,
  "accessToken": {
    "token": "eyJ0eXAiOiJKV1Qi…",
    "createdAt": "2024-01-01T00:00:00+00:00",
    "expiresAt": "2024-01-01T00:00:00+00:00"
  },
  "refreshToken": {
    "token": "eyJ0eXAiOiJKV1Qi…",
    "createdAt": "2024-01-01T00:00:00+00:00",
    "expiresAt": "2024-01-01T00:00:00+00:00"
  }
}
Not a B2COPY client yet?

Bring B2COPY to your brokerage and grow on autopilot

Launch copy trading, PAMM, and MAM on your existing servers and turn your best traders into a growth engine — with hosting, monitoring, and support included. Not sure where to start? Talk to us and we’ll walk you through it.

2–4 weeks

Time to launch

$0

Infrastructure cost

40%+

Volume increase