Authenticate your tenant
Get a bearer token from your backend and keep it there.
Every Taxbit API call carries a bearer token issued to your tenant. Your backend mints the token from credentials on the Developer Settings page in the Taxbit Dashboard, and the token never touches a browser.
By the end of this page you have a working bearer token minted from your own backend, a refresh strategy that survives expiry, and a clear split between what runs server-side and what the React SDK receives.
Before you begin
- Your
client_idandclient_secretfrom the Developer Settings page in the Taxbit Dashboard. - Your
tenant_idfrom the same page, shown there as Organization ID, if one set of credentials covers more than one tenant. - A server-side environment to hold them. Nothing on this page runs in a browser.
Request a token
Exchange your client credentials at the token endpoint with the client credentials grant, from a server you control. Include tenant_id when one set of credentials covers more than one tenant.
curl -X POST https://api.multi1.enterprise.taxbit.com/v1/oauth/token \
-H "Content-Type: application/x-www-form-urlencoded" \
--data-urlencode "grant_type=client_credentials" \
--data-urlencode "client_id=$TAXBIT_CLIENT_ID" \
--data-urlencode "client_secret=$TAXBIT_CLIENT_SECRET" \
--data-urlencode "tenant_id=$TAXBIT_TENANT_ID"A JSON body with the same fields works too.
{
"access_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6...",
"token_type": "Bearer",
"expires_in": 86400
}
Never ship the client secret to the browserThe React SDK takes a short-lived account-owner token (valid for 1 hour) that your backend fetches on the user's behalf, not your credentials. If the secret reaches client code, rotate it in Developer Settings immediately.
Use the token
Send it as an Authorization: Bearer header on every request. Tenant tokens last 24 hours (expires_in: 86400). Cache the token in your service and mint a new one before it expires. If a request comes back 401, mint a new token and retry once, so clock skew never strands a request.
curl https://api.multi1.enterprise.taxbit.com/v1/filers \
-H "Authorization: Bearer $TOKEN"Examples in these guides use $BASE_URL for https://api.multi1.enterprise.taxbit.com and $TOKEN for this access token.
If the request fails
- 400
invalid_request. The body is missinggrant_type. It must be present and set toclient_credentials, the only supported value. - 401. The
client_idorclient_secretis wrong. Copy both again from Developer Settings; a secret that was rotated no longer works.
Parameters
Only the fields used in the request above. The full schema is in the API Reference.
| Field | Type | Required | Description |
|---|---|---|---|
grant_type | string | Required | Always client_credentials. |
client_id | string | Required | Your client identifier, from Developer Settings in the Taxbit Dashboard. |
client_secret | string | Required | Store it in your secret manager, never in source control. |
tenant_id | string | Conditional | Required when one set of credentials covers more than one tenant. |
Where to go next
Set up your filer, the entity that submits returns. Account owners and accounts cannot be created until the tenant has one.
Updated 6 days ago

