Logged-In Bearer Token
This section explains obtaining a Bearer Token for a logged-in customer and outlines how an anonymous user can register to access more exclusive functionalities for UpStart Commerce Consumer APIs.
Generate a Logged-In Bearer Token
Step 1: Register as a Customer
To begin, first register as a customer to establish a more permanent customer profile through our UpStart Commerce Portal UI. Access the portal and log in using your credentials (Email and Password). If you are not already registered, you can follow this link to create your sandbox account.
For details on creating and registering Customer, go to the Customer Management Guide.
Step 2: Obtain an Anonymous Token
To obtain a logged-in bearer token, you need to obtain an anonymous token. If you have not obtained an anonymous token , visit Anonymous Bearer Token Guide for detailed information.
Step 3: Obtain an Access and Refresh Token
Copy the Curl below to obtain an Access and Refresh token and replace the following values in the header.
- Replace X-Upstart-tenant and X-Upstart-site with your specific values in the header of your request.
- Replace your "Anonymous Bearer Token" generated in Step 2 within the "Authorization" header of your request.
- Replace your "login" and "0password" with your specific values obtained while registering customers in the header.
Request:
curl --location 'https://nochannel-test-1-api.nochannel-test.upstart.team/
/v1/customer/login/token' \
--header 'Content-Type: application/json' \
--header 'X-Upstart-tenant: <your-tenantid> \
--header 'X-Upstart-site: <your-siteid> \
--header 'Authorization: Bearer: <your-bearertoken>' \
--data '{
"password":"<your-password>",
"login":"test"
}'
For more information, go to the Log-In User endpoint example request.
Step 4: Check the Status Code
Upon making an access and refresh token creation request, it responds with a status code indicating the outcome.
- Success (HTTP 200): The server has successfully processed your request.
- Error Responses: HTTP 401: The server was unable to process the request. Check and ensure that the provided credentials are valid. HTTP 403: The request contains valid credentials, but the user's roles may be insufficient or the credentials may be expired.
Step 5: Access and Refresh Token Obtained Successfully
After executing the Curl above, you have successfully obtained a valid response for an "accessToken" and "refreshToken". Copy these values and paste them into the authorization field.
Response:
{
"accessToken": "<your-accesstoken>",
"refreshToken": "<your-refreshtoken>"
}Access tokens serve as short-term credentials for accessing UpStart Commerce APIs, while Refresh tokens act as a mechanism to renew access tokens and maintain customer sessions over a more extended period during exploration.
Make Your First API Call with Logged-In Bearer Token
To make your first call by using a Logged-In Bearer Token, you need to replace your above obtained "Logged-In Bearer Token" in the request authorization header by using the Curl below.
Request:
curl --location 'https://nochannel-test-1-api.nochannel-test.upstart.team/v1/customer/profile' \
--header 'X-UpStart-tenant: <your-tenantid>' \
--header 'Content-Type: application/json' \
--header 'X-Upstart-site: <your-siteid>' \
--header 'Authorization: Bearer <accessToken obtained from step 5>'\Response:
{
"addresses": {
"addresses": [
{
"businessName": "TeleSalesGuru",
"city": "Conneticut",
"country": "Stamford",
"county": "United States",
"label": "Home",
"name": {
"first": "John",
"last": "Doe",
"middleInitial": "D.",
"salutation": "Mr.",
"suffix": "Sr."
},
"phoneNumber": "12031234567",
"poBox": false,
"postalCode": "06901",
"stateOrRegion": "CT",
"street1": "1 Landmark Square",
"street2": "Avenue Square"
}
],
"defaultBilling": {
"businessName": "TeleSalesGuru",
"city": "Conneticut",
"country": "Stamford",
"county": "United States",
"label": "Home",
"name": {
"first": "John",
"last": "Doe",
"middleInitial": "D.",
"salutation": "Mr.",
"suffix": "Sr."
},
"phoneNumber": "12031234567",
"poBox": false,
"postalCode": "06901",
"stateOrRegion": "CT",
"street1": "1 Landmark Square",
"street2": "Avenue Square"
},
"defaultShipping": {
"businessName": "TeleSalesGuru",
"city": "Conneticut",
"country": "Stamford",
"county": "United States",
"label": "Home",
"name": {
"first": "John",
"last": "Doe",
"middleInitial": "D.",
"salutation": "Mr.",
"suffix": "Sr."
},
"phoneNumber": "12031234567",
"poBox": false,
"postalCode": "06901",
"stateOrRegion": "CT",
"street1": "1 Landmark Square",
"street2": "Avenue Square"
}
},
"birthDate": "1991-05-17",
"creditCards": {
"cards": [
{
"cardNumber": "8111",
"cardType": "Visa",
"expirationMonth": "10",
"expirationYear": "2025",
"label": "Personal",
"token": "65FZG3456Z756JH345"
}
],
"default": {
"cardNumber": "8111",
"cardType": "Visa",
"expirationMonth": "10",
"expirationYear": "2025",
"label": "Personal",
"token": "65FZG32BYZ75456345"
}
},
"defaultLocationId": "ced8ef74-c968-47f6-98e0-d780d3da85fb",
"emailAddresses": {
"addresses": [
{
"address": "[email protected]",
"label": "Work email"
}
],
"default": {
"address": "[email protected]",
"label": "Work email"
}
},
"gender": "m",
"id": "ced8wf74-c968-47f6-98e0-CBe5fb",
"login": "bob.smith.29",
"name": {
"first": "Bob",
"last": "Smith",
"middleInitial": "D.",
"salutation": "Capt.",
"suffix": "Sr."
},
"registrationDate": "2020-07-21T17:32:28Z",
"siteIds": [
"c60e4f26-cb81-41c5-a1aa-856550be5228"
],
"subscriptions": {
"addressCatalogs": [
{
"address": {
"businessName": "TeleSalesGuru",
"city": "Conneticut",
"country": "Stamford",
"county": "United States",
"label": "Home",
"name": {
"first": "John",
"last": "Doe",
"middleInitial": "D.",
"salutation": "Mr.",
"suffix": "Sr."
},
"phoneNumber": "12031234567",
"poBox": false,
"postalCode": "06901",
"stateOrRegion": "CT",
"street1": "1 Landmark Square",
"street2": "Avenue Square"
},
"label": "The Big Catalog"
}
],
"emailCatalogs": [
{
"email": "[email protected]",
"label": "Daily Deals"
}
],
"emailNewsletters": [
{
"email": "[email protected]",
"label": "NewsLetter"
}
]
}
}For more information, go to the Get Customer Profile endpoint example request.
Upon receiving the successful response to the Get Customer Profile request, you have completed your first UpStart Commerce Consumer API call, using the logged-in bearer token.