> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.modernfi.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.modernfi.com/_mcp/server.

# Authentication

ModernFi's approach to authentication is designed to ensure the security and safety of user data and assets. Follow these steps to get up and running with the ModernFi API.

## 1. Obtain Client ID and Secret

To get your `Client ID` and `Client Secret`, [contact](mailto:support@modernfi.com)the ModernFi team. When reaching out, let your representative know whether you need **read-only** or **read+write** access:

* **Read-only**: retrieve accounts, depositors, transactions, and statements without the ability to modify records.
* **Read+write**: full access to retrieve and create or modify records.

ModernFi will onboard your institution and share the corresponding credentials via SendSafely.

## 2. Request an Access Token

With your `Client ID` and `Client Secret`, make a request to the `oauth2/token` endpoint to receive an access\_token.

```shell
# export client ID / secret as env var
export MODERNFI_CLIENT_ID="my-client-id"
export MODERNFI_CLIENT_SECRET="my-client-secret"
export MODERNFI_AUDIENCE="https://api.modernfi.com"
curl --request POST \
     --url https://auth.modernfi.com/oauth/token \
     --header 'content-type: application/json' \
     --data '{"client_id": $MODERNFI_CLIENT_ID, "client_secret": $MODERNFI_CLIENT_SECRET, "audience": $MODERNFI_AUDIENCE, "grant_type": "client_credentials"}'
```

**`python`**

```python python
import requests

# Define the client credentials and audience
client_id = "my-client-id"
client_secret = "my-client-secret"

# Prepare the data for the request
data = {
    "client_id": client_id,
    "client_secret": client_secret,
    "audience": "https://api.modernfi.com",
    "grant_type": "client_credentials"
}

# Make the request
response = requests.post(
    "https://auth.modernfi.com/oauth/token",
    json=data,
    headers={"content-type": "application/json"}
)
```

The response is of the following shape:

```json
{
  "access_token": "eyJraWQiOiI3Yll...",
  "expires_in": 86400,
  "token_type": "Bearer"
}
```

## 3. Pass the Token in Your API Call Headers

To pass your user token to ModernFi APIs, add it as a header to your API calls in the following format:

```
Authorization: "Bearer {{your user_token here}}"
```

If, for example, your API token were `eyJraWQiOiI3Yll`, your authorization header will be:

```
Authorization: "Bearer eyJraWQiOiI3Yll"
```

Here is an example API call that properly sets the authorization header:

```bash
curl --request GET \
     --url https://api.modernfi.com/digital-banking/v1/accounts \
     --header 'accept: application/json' \
     --header 'authorization: Bearer eyJraWQiOiI3Yll' \
     --header 'content-type: application/json'
```

```python
import requests

# Set the access token
access_token = "Bearer eyJraWQiOiI3Yll"

# Make the GET request
response = requests.get(
    "https://api.modernfi.com/v2/digital-banking/accounts",
    headers={
        "accept": "application/json",
        "authorization": access_token,
        "content-type": "application/json"
    }
)

```

### **Token Expiration and Caching**

Access tokens have a TTL of 86400 seconds (24 hours). We recommend caching your token and reusing it across API calls rather than requesting a new token on each request. When the token expires, simply request a new one using the same credentials.

If you need to revoke a token before it expires, [contact](mailto:support@modernfi.com)your ModernFi representative.