logo

Experian Connect API

OAuth 2.0 Authentication

Overview

All ConnectAPI endpoints are protected using OAuth 2.0 through Experian's API Gateway (Apigee). Before invoking any ConnectAPI endpoint, applications must obtain an Access Token from the OAuth Authorization Server. The Access Token is then included as a Bearer Token in the HTTP Authorization header.

Base URLs

Environment Base URL
UAT https://uat-us-api.experian.com/
Production https://us-api.experian.com/

Authentication Flow

  1. Request an Access Token.
  2. Call ConnectAPI using the Access Token.
  3. Refresh the Access Token when it expires.
  4. Optionally revoke the token.

Step 1 - Request an Access Token

Authenticate against the OAuth Authorization Server to obtain an Access Token and Refresh Token.

Token Endpoint

POST https://uat-us-api.experian.com/oauth2/v1/token

Required Headers

Header Description
client_id Application identifier.
client_secret Application secret.
Content-Type application/json

Request Body

{
    "username": "<USERNAME>",
    "password": "<PASSWORD>"
}

Successful Response

{
    "issued_at": "1509914612223",
    "expires_in": "1800",
    "token_type": "Bearer",
    "access_token": "<ACCESS_TOKEN>",
    "refresh_token": "<REFRESH_TOKEN>"
}

Response Parameters

Parameter Description
issued_at Timestamp indicating when the token was issued.
expires_in Access Token lifetime in seconds (1800).
token_type Always Bearer.
access_token Token used to authenticate API requests.
refresh_token Token used to obtain a new Access Token.

Step 2 - Call ConnectAPI

Include the Access Token in every API request using the Authorization header.

Authorization: Bearer <ACCESS_TOKEN>

Example Request

curl --request POST \
https://uat-us-api.experian.com/connectapi/v3/auth/authstatus/ZjhhZWY3YzYtYmI4Yi00MzFlLThhMjMtY2NiYzA5MGFiNzQw \
--header "Authorization: Bearer <ACCESS_TOKEN>" \
--header "Accept: application/json"

Step 3 - Refresh an Access Token

When the Access Token expires, request a new one using the associated Refresh Token.

POST /oauth2/v1/token

grant_type=refresh_token
client_id=<CLIENT_ID>
client_secret=<CLIENT_SECRET>
refresh_token=<REFRESH_TOKEN>

Step 4 - Revoke Tokens

Applications may revoke an Access Token or Refresh Token when it is no longer required.

POST /oauth2/v1/revokeToken

client_id=<CLIENT_ID>
client_secret=<CLIENT_SECRET>
token=<ACCESS_TOKEN>

Successful Response: HTTP 200 OK

Token Lifetime

Token Lifetime
Access Token 30 minutes
Refresh Token 24 hours

Best Practice - Token Caching

Cache the Access Token after it is generated and reuse it for API requests during its lifetime. Generate a replacement token approximately 28-29 minutes after issuance to minimize unnecessary authentication requests and improve application performance.

Authentication Errors

HTTP Status Description
400 Bad Request. Client ID/Client Secret are missing. Username/password is missing or blank.
401 Unauthorized. Expired Access Token (access token is invalid). Username/password mismatch. Incorrect Client ID/Client Secret. Authorization fails as account is not in active status.
403 Forbidden. IP range or Time of Day validation fails. Access to the requested resource is Forbidden.
405 Access token request with HTTP method other than POST. Method Not Allowed. The requested method is not allowed.
415 Content-Type is missing or Unsupported Media Type.
500 Internal Server Error. If problems persist, please contact TSCTenantScreeningSupport@experian.com

Security Recommendations

  • Protect client_secret and Refresh Tokens.
  • Never log Access Tokens.
  • Cache tokens securely.
  • Revoke tokens that are no longer needed.

Support

For authentication or authorization assistance, contact:

TSCTenantScreeningSupport@experian.com