---
title: "Common & authentication API"
canonical: https://documentation.maventa.com/api-specification/rest-api/common-and-authentication-api/
---

The Common & Authentication API handles OAuth2-based authentication for all Maventa REST APIs. Use it to obtain and manage the bearer tokens that authorize requests across all other APIs. It also provides endpoints to verify authentication status and retrieve company information.

For a full explanation of the authentication flow and how to get started, see the [REST API Getting Started guide](https://documentation.maventa.com/api-specification/rest-api/getting-started/).

## API endpoints

### POST /oauth2/token

OAuth2 token endpoint

The endpoint enables a registered company to obtain a OAuth 2 Bearer Token, which can be used to access the companys data in all the future API calls.
 A token will be active for 60 minutes.
 #### Scopes
 Scopes let you specify what type of access you need and limit access for granted OAuth tokens.

 | Scope | Description |
 |-------|-------------|
                            eui|  Recommended to use when integrating to EUI. Alias for eui:open, company:read, company:write, lookup, receivables:assignments, document:send, document:receive, invoice:receive, invoice:send, analysis|
                        global|                                                                                                                                         Alias for company:read, document:receive, document:send, lookup|
                       company|                                                                                                                                                                   Alias for company:read, company:write|
                        lookup|                                                                                                                                                                  grants access to the lookup operations|
              document:receive|                                                                                                                                                            grants access to document receive operations|
                 document:send|                                                                                                                                                               grants access to document send operations|
               invoice:receive|                                                                                                                                                             grants access to invoice receive operations|
                  invoice:send|                                                                                                                                                                grants access to invoice send operations|
                  company:read|                                                                                                                                      grants read access to company settings, profiles and notifications|
                 company:write|                                                                                                                                     grants write access to company settings, profiles and notifications|
                      validate|                                                                                                                                                      grants access to the AutoInvoice validator service|
       receivables:assignments|                                                                                                                                                 grants access to assignments in the collection services|
                      analysis|                                                                                                                                                                       grants access to analysis service|
               billing:reports|                                                                                                                                                                        grants access to billing reports|
partner:invoice_delivery_actions|                                                                                                                                                                grants access to partner invoice actions|
               partner:lookups|                                                                                                                                                                 grants access to partner lookup actions|
             partner:takeovers|                                                                                                                                                                      grants access to partner takeovers|
  partner:lyanthe_scan_service|                                                                                                                                                   grants access to partner lyanthe scan service actions|
          fi_bank_message:send|                                                                                                                                                        grants access to FI bank message send operations|
       fi_bank_message:receive|                                                                                                                                                     grants access to FI bank message receive operations|
    operator:documents:receive|                                                                                                                                                               grants access to fetch received documents|
       operator:documents:send|                                                                                                                                                                         grants access to send documents|
               operator:lookup|                                                                                                                                                     grants access to perform actions related to lookups|
         operator:participants|                                                                                                                                               grants access to perform actions on operator participants|
        operator:notifications|                                                                                                                                              grants access to perform actions on operator notifications|
             operator:validate|                                                                                                                                                      grants access to the AutoInvoice validator service|
operator:receivables:assignments|                                                                                                                                                 grants access to assignments in the collection services|
operator:receivables:assignments:create|                                                                                                                                          grants access to create assignments in the collection services|
 operator:receivables:webhooks|                                                                                                                                                      grants access to send collection services webhooks|
operator:receivables:account_statement|                                                                                                                                                                     grants access to account statements|
             operator:analysis|                                                                                                                                                                       grants access to analysis service|
            operator:companies|                                                                                                                                                               grants access to fetch operator companies|
             operator:takeover|                                                                                                                                                             grants access to execute a company takeover|
      operator:billing:actions|                                                                                                                                                               grants access to operator billing actions|
operator:sending_parties:write|                                                                                                                                                                  grants access to write sending parties|
operator:supplier_bank_accounts:write|                                                                                                                                                           grants access to write supplier bank accounts|
          operator:user:create|                                                                                                                                                                          grants access to create a user|
         operator:company:read|                                                                                                                                                                  grants access to read company profiles|
        operator:company:write|                                                                                                                                                                 grants access to write company profiles

 If no scope is defined, the token request will default to use the scopes ```global``` and ```company```. The granted scopes will be returned in the response.
 #### Vendor API key and license data
 To identify the application a valid ```vendor_api_key``` should be provided in the token request. Additional license data can be provided as JSON in the ```license_data``` parameter:
 ```
{
  "key": "C84411ED-5639-4B48-83D0-B718BB9DA0F7", // License key of software making the call
  "meta": {
    "licensing":   "VLS",       // Information about the licensing system
    "erp_name":    "Visma ERP", // Name of ERP
    "erp_version": "1.1",       // Current version number of ERP
    "erp_user":    "rbaardse"   // Local ERP user name
  }
}
```

**Parameters**

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| grant_type | formData | string | yes | The grant type |
| client_id | formData | string | no | The client id |
| client_secret | formData | string | no | The client secret |
| scope | formData | string | no | Scope of the requested token |
| vendor_api_key | formData | string | no | Software API key |
| license_data | formData | string | no | License data |

**Responses**

| Status | Description | Schema |
| --- | --- | --- |
| 200 | Granted access token | `API_Entities_OAuthToken` |

### GET /oauth2/current

Fetch information about the authenticated user and company

**Responses**

| Status | Description | Schema |
| --- | --- | --- |
| 200 | Fetch information about the authenticated user and company | `API_Entities_OAuthCurrent` |

### GET /status/authenticated

Status requiring authentication

Returns information of currently authenticated identity. Only for testing purposes.

**Responses**

| Status | Description | Schema |
| --- | --- | --- |
| 200 | Status requiring authentication | `API_Entities_Status` |

### GET /v1/jwk


List the public keys of this API

**Responses**

| Status | Description | Schema |
| --- | --- | --- |
| 200 | List the public keys of this API | `array[API_Entities_JWKEntries]` |

### GET /odp/companies/{id}


Fetch ODP company by id

**Parameters**

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| id | path | integer | yes | ID of ODP company |

**Responses**

| Status | Description | Schema |
| --- | --- | --- |
| 200 | Fetch ODP company by id | `OdpCompany` |

### PATCH /odp/companies/{id}


Update existing ODP company or create a new one if missing

**Parameters**

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| id | path | integer | yes | ID of ODP company |
| trusted | formData | boolean | yes | Is company trusted |

**Responses**

| Status | Description | Schema |
| --- | --- | --- |
| 204 | Company updated succesfully |  |


_OpenAPI spec snapshot: 2026-05-06_
