← Back to Sample APIs

Get JWT Bearer Token

POST your api_key and api_secret to receive a signed JWT (JSON Web Token). Use this token in the Authorization: Bearer header of the next API call. Token is valid for 1 hour.

Concept: JWT Token Generation · OAuth 2.0 style flow
Addition API Series — same operation, different style
01

Endpoint

POST https://labs.lowcademy.com/apis/add-token
1
POST api_key + api_secret to this endpoint → receive a JWT token
2
Use the JWT as Authorization: Bearer <token> when calling add-bearer.php
02

Credentials

Lab Credentials — For Training Use Only

api_keylc-api-key-2024
api_secretlc@Secret#2024
03

Request Body (JSON)

FieldTypeRequiredDescription
api_keyStringRequiredYour API key
api_secretStringRequiredYour API secret
{
  "api_key"   : "lc-api-key-2024",
  "api_secret": "lc@Secret#2024"
}
04

Sample Requests

cURL

curl -X POST https://labs.lowcademy.com/apis/add-token \
     -H "Content-Type: application/json" \
     -d '{"api_key":"lc-api-key-2024","api_secret":"lc@Secret#2024"}'

JavaScript (fetch)

const res = await fetch('https://labs.lowcademy.com/apis/add-token', {
  method : 'POST',
  headers: { 'Content-Type': 'application/json' },
  body   : JSON.stringify({ api_key: 'lc-api-key-2024', api_secret: 'lc@Secret#2024' })
});
const { token } = await res.json();
// Now use token in the next API call
05

Response — 200 OK

FieldTypeDescription
successBooleanAlways true
tokenStringSigned JWT (HS256). Use as: Authorization: Bearer <token>
token_typeStringAlways "Bearer"
expires_inIntegerSeconds until expiry — always 3600 (1 hour)
expires_atStringHuman-readable expiry timestamp
{
  "success"   : true,
  "token"     : "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJhcGlfdXNlciIsImlzcyI6ImxhYnMubG93Y2FkZW15LmNvbSIsImlhdCI6MTcyMDc4MDAwMCwiZXhwIjoxNzIwNzgzNjAwfQ.xxxxxxxxxxx",
  "token_type": "Bearer",
  "expires_in": 3600,
  "expires_at": "2026-07-12 11:30:00"
}
06

Error Responses

200
OK — Token returned. Copy it and use in add-bearer.php.
401
Unauthorized — Invalid api_key or api_secret.
400
Bad Request — Missing or invalid JSON body.
405
Method Not Allowed — Use POST.