Refresh auth token
Refresh auth token of the connected institution. Some institutions do not require tokens to be refreshed.
The following institutions require custom flows:
WeBull: AuthToken should be provided along with the RefreshToken
Vanguard: security settings may activate MFA, requiring user action. If MFA is triggered, a second refresh request should be sent. Second request should contain MFA code and access token obtained from initial response
curl --request POST \
--url https://integration-api.meshconnect.com/api/v1/token/refresh \
--header 'Content-Type: application/json' \
--header 'X-Client-Id: <api-key>' \
--header 'X-Client-Secret: <api-key>' \
--data '
{
"refreshToken": "Secret refresh token",
"type": "coinbase"
}
'import requests
url = "https://integration-api.meshconnect.com/api/v1/token/refresh"
payload = {
"refreshToken": "Secret refresh token",
"type": "coinbase"
}
headers = {
"X-Client-Secret": "<api-key>",
"X-Client-Id": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'X-Client-Secret': '<api-key>',
'X-Client-Id': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({refreshToken: 'Secret refresh token', type: 'coinbase'})
};
fetch('https://integration-api.meshconnect.com/api/v1/token/refresh', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://integration-api.meshconnect.com/api/v1/token/refresh",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'refreshToken' => 'Secret refresh token',
'type' => 'coinbase'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-Client-Id: <api-key>",
"X-Client-Secret: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://integration-api.meshconnect.com/api/v1/token/refresh"
payload := strings.NewReader("{\n \"refreshToken\": \"Secret refresh token\",\n \"type\": \"coinbase\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-Client-Secret", "<api-key>")
req.Header.Add("X-Client-Id", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://integration-api.meshconnect.com/api/v1/token/refresh")
.header("X-Client-Secret", "<api-key>")
.header("X-Client-Id", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"refreshToken\": \"Secret refresh token\",\n \"type\": \"coinbase\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://integration-api.meshconnect.com/api/v1/token/refresh")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-Client-Secret"] = '<api-key>'
request["X-Client-Id"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"refreshToken\": \"Secret refresh token\",\n \"type\": \"coinbase\"\n}"
response = http.request(request)
puts response.read_body{
"content": {
"status": "succeeded",
"expiresInSeconds": 86400,
"brokerAccountTokens": [
{
"accessToken": "New secret token",
"refreshToken": "New secret refresh token"
}
]
},
"status": "ok",
"message": "",
"errorHash": "9d3039e8",
"teamCode": "P4",
"errorType": ""
}{
"status": "badRequest",
"message": "Unauthorized token",
"displayMessage": "Could not refresh the authentication token. The provided data is not correct",
"errorHash": "1bc4f94f",
"teamCode": "P4",
"errorType": "badRequest"
}Authorizations
Contact Mesh to get client Secret
Contact Mesh to get client Id
Body
robinhood, eTrade, alpaca, tdAmeritrade, weBull, stash, interactiveBrokers, public, coinbase, kraken, coinbasePro, cryptoCom, openSea, binanceUs, gemini, cryptocurrencyAddress, cryptocurrencyWallet, okCoin, bittrex, kuCoin, etoro, cexIo, binanceInternational, bitstamp, gateIo, acorns, okx, bitFlyer, coinlist, huobi, bitfinex, deFiWallet, krakenDirect, vanguard, binanceInternationalDirect, bitfinexDirect, bybit, paxos, coinbasePrime, btcTurkDirect, kuCoinDirect, okxOAuth, paribuDirect, robinhoodConnect, blockchainCom, bitsoDirect, binanceConnect, binanceOAuth, revolutConnect, binancePay, bybitDirect, paribuOAuth, payPalConnect, binanceTrDirect, coinbaseRamp, bybitDirectMobile, sandbox, cryptoComPay, bybitEuDirect, uphold, binancePayOnchain, sandboxCoinbase, bybitPay, krakenOAuth, bluvoKrakenOAuth, cashApp, sandboxKrakenOAuth, krakPay, unlimit, alchemyPay, okxPay, bybitPayPsp 1Optional, used when we the refresh token should be refreshed. Currently this flow is supported by TD Ameritrade
Some institutions may require accessToken to be provided as well. It's currently required by WeBull and Vanguard
Currently used to update WeBull trade token.
Optional, currently used by Vanguard if account has enforced MFA enabled.
Additional metadata
Show child attributes
Show child attributes
Response
OK
ok, serverFailure, permissionDenied, badRequest, notFound, conflict, tooManyRequest, locked, unavailableForLegalReasons A message generated by the API
User-friendly display message that can be presented to the end user
An error grouping hash from string components and caller information. Used by bugsnag on FE for correct error grouping
Opaque team code for error routing. Resolved from exception origin or caller file path via CODEOWNERS. Format: 2-character code (e.g., "7K", "M2"). Use for alerting/routing, not display.
Strictly-typed error type that is explaining the reason of an unsuccessful status of the operation. All possible error types are available in the documentation.
Show child attributes
Show child attributes
Was this page helpful?
curl --request POST \
--url https://integration-api.meshconnect.com/api/v1/token/refresh \
--header 'Content-Type: application/json' \
--header 'X-Client-Id: <api-key>' \
--header 'X-Client-Secret: <api-key>' \
--data '
{
"refreshToken": "Secret refresh token",
"type": "coinbase"
}
'import requests
url = "https://integration-api.meshconnect.com/api/v1/token/refresh"
payload = {
"refreshToken": "Secret refresh token",
"type": "coinbase"
}
headers = {
"X-Client-Secret": "<api-key>",
"X-Client-Id": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'X-Client-Secret': '<api-key>',
'X-Client-Id': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({refreshToken: 'Secret refresh token', type: 'coinbase'})
};
fetch('https://integration-api.meshconnect.com/api/v1/token/refresh', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://integration-api.meshconnect.com/api/v1/token/refresh",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'refreshToken' => 'Secret refresh token',
'type' => 'coinbase'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-Client-Id: <api-key>",
"X-Client-Secret: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://integration-api.meshconnect.com/api/v1/token/refresh"
payload := strings.NewReader("{\n \"refreshToken\": \"Secret refresh token\",\n \"type\": \"coinbase\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-Client-Secret", "<api-key>")
req.Header.Add("X-Client-Id", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://integration-api.meshconnect.com/api/v1/token/refresh")
.header("X-Client-Secret", "<api-key>")
.header("X-Client-Id", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"refreshToken\": \"Secret refresh token\",\n \"type\": \"coinbase\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://integration-api.meshconnect.com/api/v1/token/refresh")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-Client-Secret"] = '<api-key>'
request["X-Client-Id"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"refreshToken\": \"Secret refresh token\",\n \"type\": \"coinbase\"\n}"
response = http.request(request)
puts response.read_body{
"content": {
"status": "succeeded",
"expiresInSeconds": 86400,
"brokerAccountTokens": [
{
"accessToken": "New secret token",
"refreshToken": "New secret refresh token"
}
]
},
"status": "ok",
"message": "",
"errorHash": "9d3039e8",
"teamCode": "P4",
"errorType": ""
}{
"status": "badRequest",
"message": "Unauthorized token",
"displayMessage": "Could not refresh the authentication token. The provided data is not correct",
"errorHash": "1bc4f94f",
"teamCode": "P4",
"errorType": "badRequest"
}