> ## Documentation Index
> Fetch the complete documentation index at: https://bmpmoneyplus-sandbox.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

## Authentication Method

We utilize the OAuth 2.0 authentication method, an industry standard for authorization, to ensure the security and integrity of user and system identification. This method involves the generation of tokens that allow secure access to our servers, software, and APIs. Authentication through OAuth 2.0 helps prevent cyber fraud and the leakage of confidential information by using public key encryption to validate identities.

<Steps>
  <Step title="Creation of Public and Private Keys">
    Before receiving the credential, it is necessary to generate a pair of keys: one private key and one public key. The private key will be used to sign the token, while the public key should be sent to us to validate the signature of the token.

    First, generate the **private key** using the command below via terminal:

    ```bash theme={null}
    openssl genrsa -out private.pem 2048
    ```

    Next, generate the **public key** through the terminal:

    ```bash theme={null}
    openssl rsa -in private.pem -pubout > public.pem
    ```

    <Warning> Keep the private key in a secure location and never share it.</Warning>
  </Step>

  <Step title="Request for Public Key">
    We will request your email to open a request regarding the sending of the public key. After that, you will receive a message from **[notifications@heflo.com](mailto:notifications@heflo.com)** with instructions for sending the key.

    <Warning>Send **only** your public key for validation to our team, responding to the HEFLO request email, without adding other people in copy for security reasons. If other people are copied, it will invalidate the receipt of the public key.</Warning>
  </Step>

  <Step title="Receiving the client_id">
    After validating your public key, our team will generate and send your `client_id`, which will be used for authentication in the system.
  </Step>

  <Step title="Generating the JWT">
    Generate a TOKEN following the **RS256** standard, containing crucial information such as unique identifier, issuance time, and expiration.

    ```javascript theme={null}
    const tokenHeader = {
    alg: "RS256", // 'alg': Algorithm used to sign the token (RS256 - RSA with SHA-256).
    typ: "JWT"    // 'typ': Type of token, in this case, JWT.
    };

    const tokenPayload = {
    jti: "5e8e07e3-d3f0-4881-a644-0895f4949e9b", // 'jti': Unique ID of the token.
    sub: "client_id", // 'sub': Client identifier (fill in with the client_id sent by our team).
    iat: 1573648398, // 'iat': Date and time when the token was issued (UNIX timestamp in seconds).
    nbf: 1573648398, // 'nbf': Date and time before which the token should not be accepted (UNIX timestamp).
    exp: 1573648458, // 'exp': Expiration date of the token (UNIX timestamp).
    iss: "client_id", // 'iss': Token issuer (fill in with the client_id sent by our team).
    aud: "https://auth.moneyp.dev.br/connect/token" // 'aud': Recipient of the token (verifies if the token is sent to the correct server).
    };
    ```
  </Step>

  <Step title="Bearer Token Generation Endpoint">
    To generate a TOKEN using the OAuth 2.0 method, the client must send a POST request with the Header Content-Type "application/x-www-form-urlencoded," below is the CURL of the endpoint that will be used to generate the token:

    ```javascript theme={null}
        curl --location 'https://auth.moneyp.dev.br/connect/token'   --header 'Content-Type: application/x-www-form-urlencoded'   --header 'Cache-Control: no-cache'   --data-urlencode 'grant_type=client_credentials'   --data-urlencode 'client_id=client_id'   --data-urlencode 'scope=bmp.digital.api.full.access'   --data-urlencode 'client_assertion= "<< JWT Token >>"' \ // JWT generated in the previous step.
      --data-urlencode 'client_assertion_type=urn:ietf:params:oauth:client-assertion-type:jwt-bearer'
    ```

    After authentication, the access token obtained should be used in all subsequent requests in the authorization header.

    ```javascript theme={null}
    const headers = {
      Authorization: `Bearer <<Access token>>`
      };
    ```

    <Warning>***Our Bearer Token, once generated, has a validity of 1 hour. After this period, it will be necessary to generate a new token to ensure the continuity of the session in an active and secure manner.***</Warning>
  </Step>
</Steps>
