Experian Connect API
OAuth 2.0 Authentication
Overview
All ConnectAPI endpoints are protected using OAuth 2.0 through Experian's API Gateway (Apigee). Before invoking any ConnectAPI endpoint, applications must obtain an Access Token from the OAuth Authorization Server. The Access Token is then included as a Bearer Token in the HTTP Authorization header.
Base URLs
| Environment | Base URL |
|---|---|
| UAT | https://uat-us-api.experian.com/ |
| Production | https://us-api.experian.com/ |
Authentication Flow
- Request an Access Token.
- Call ConnectAPI using the Access Token.
- Refresh the Access Token when it expires.
- Optionally revoke the token.
Step 1 - Request an Access Token
Authenticate against the OAuth Authorization Server to obtain an Access Token and Refresh Token.
Token Endpoint
POST https://uat-us-api.experian.com/oauth2/v1/token
Required Headers
| Header | Description |
|---|---|
| client_id | Application identifier. |
| client_secret | Application secret. |
| Content-Type | application/json |
Request Body
{
"username": "<USERNAME>",
"password": "<PASSWORD>"
}
Successful Response
{
"issued_at": "1509914612223",
"expires_in": "1800",
"token_type": "Bearer",
"access_token": "<ACCESS_TOKEN>",
"refresh_token": "<REFRESH_TOKEN>"
}
Response Parameters
| Parameter | Description |
|---|---|
| issued_at | Timestamp indicating when the token was issued. |
| expires_in | Access Token lifetime in seconds (1800). |
| token_type | Always Bearer. |
| access_token | Token used to authenticate API requests. |
| refresh_token | Token used to obtain a new Access Token. |
Step 2 - Call ConnectAPI
Include the Access Token in every API request using the Authorization header.
Authorization: Bearer <ACCESS_TOKEN>
Example Request
curl --request POST \ https://uat-us-api.experian.com/connectapi/v3/auth/authstatus/ZjhhZWY3YzYtYmI4Yi00MzFlLThhMjMtY2NiYzA5MGFiNzQw \ --header "Authorization: Bearer <ACCESS_TOKEN>" \ --header "Accept: application/json"
Step 3 - Refresh an Access Token
When the Access Token expires, request a new one using the associated Refresh Token.
POST /oauth2/v1/token grant_type=refresh_token client_id=<CLIENT_ID> client_secret=<CLIENT_SECRET> refresh_token=<REFRESH_TOKEN>
Step 4 - Revoke Tokens
Applications may revoke an Access Token or Refresh Token when it is no longer required.
POST /oauth2/v1/revokeToken client_id=<CLIENT_ID> client_secret=<CLIENT_SECRET> token=<ACCESS_TOKEN>
Successful Response: HTTP 200 OK
Token Lifetime
| Token | Lifetime |
|---|---|
| Access Token | 30 minutes |
| Refresh Token | 24 hours |
Best Practice - Token Caching
Authentication Errors
| HTTP Status | Description |
|---|---|
| 400 | Bad Request. Client ID/Client Secret are missing. Username/password is missing or blank. |
| 401 | Unauthorized. Expired Access Token (access token is invalid). Username/password mismatch. Incorrect Client ID/Client Secret. Authorization fails as account is not in active status. |
| 403 | Forbidden. IP range or Time of Day validation fails. Access to the requested resource is Forbidden. |
| 405 | Access token request with HTTP method other than POST. Method Not Allowed. The requested method is not allowed. |
| 415 | Content-Type is missing or Unsupported Media Type. |
| 500 | Internal Server Error. If problems persist, please contact TSCTenantScreeningSupport@experian.com |
Security Recommendations
- Protect client_secret and Refresh Tokens.
- Never log Access Tokens.
- Cache tokens securely.
- Revoke tokens that are no longer needed.
Support
For authentication or authorization assistance, contact:
TSCTenantScreeningSupport@experian.com
