Authenticate your tenant

Get a bearer token from your backend and keep it there.

Every Taxbit API call carries a bearer token issued to your tenant. Your backend mints the token from credentials on the Developer Settings page in the Taxbit Dashboard, and the token never touches a browser.

By the end of this page you have a working bearer token minted from your own backend, a refresh strategy that survives expiry, and a clear split between what runs server-side and what the React SDK receives.

Before you begin

  • Your client_id and client_secret from the Developer Settings page in the Taxbit Dashboard.
  • Your tenant_id from the same page, shown there as Organization ID, if one set of credentials covers more than one tenant.
  • A server-side environment to hold them. Nothing on this page runs in a browser.

Request a token

Exchange your client credentials at the token endpoint with the client credentials grant, from a server you control. Include tenant_id when one set of credentials covers more than one tenant.

curl -X POST https://api.multi1.enterprise.taxbit.com/v1/oauth/token \
  -H "Content-Type: application/x-www-form-urlencoded" \
  --data-urlencode "grant_type=client_credentials" \
  --data-urlencode "client_id=$TAXBIT_CLIENT_ID" \
  --data-urlencode "client_secret=$TAXBIT_CLIENT_SECRET" \
  --data-urlencode "tenant_id=$TAXBIT_TENANT_ID"

A JSON body with the same fields works too.

{
  "access_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6...",
  "token_type": "Bearer",
  "expires_in": 86400
}
❗️

Never ship the client secret to the browser

The React SDK takes a short-lived account-owner token (valid for 1 hour) that your backend fetches on the user's behalf, not your credentials. If the secret reaches client code, rotate it in Developer Settings immediately.

Use the token

Send it as an Authorization: Bearer header on every request. Tenant tokens last 24 hours (expires_in: 86400). Cache the token in your service and mint a new one before it expires. If a request comes back 401, mint a new token and retry once, so clock skew never strands a request.

curl https://api.multi1.enterprise.taxbit.com/v1/filers \
  -H "Authorization: Bearer $TOKEN"

Examples in these guides use $BASE_URL for https://api.multi1.enterprise.taxbit.com and $TOKEN for this access token.

If the request fails

  • 400 invalid_request. The body is missing grant_type. It must be present and set to client_credentials, the only supported value.
  • 401. The client_id or client_secret is wrong. Copy both again from Developer Settings; a secret that was rotated no longer works.

Parameters

Only the fields used in the request above. The full schema is in the API Reference.

FieldTypeRequiredDescription
grant_typestringRequiredAlways client_credentials.
client_idstringRequiredYour client identifier, from Developer Settings in the Taxbit Dashboard.
client_secretstringRequiredStore it in your secret manager, never in source control.
tenant_idstringConditionalRequired when one set of credentials covers more than one tenant.

Where to go next

Set up your filer, the entity that submits returns. Account owners and accounts cannot be created until the tenant has one.