Authentication
Learn how to authenticate your API requests to Apache Fineract.
HTTP Basic Authentication
Fineract uses HTTP Basic Authentication for API requests. You need to include your credentials encoded in Base64 in the Authorization header, along with the tenant identifier.
Security Note: Always use HTTPS in production. Never expose your credentials in client-side code or version control.
Required Headers
AuthorizationBasic authentication credentials encoded in Base64
Fineract-Platform-TenantIdYour tenant identifier (default: "default")
Content-TypeSet to "application/json" for JSON payloads
Example Requests
curl --request GET \
--url "https://your-fineract-instance.com/fineract-provider/api/v1/clients" \
--header "Authorization: Basic $(echo -n 'username:password' | base64)" \
--header "Fineract-Platform-TenantId: default" \
--header "Content-Type: application/json"OAuth2 Authentication (Optional)
Fineract also supports OAuth2 for enhanced security. To use OAuth2, first obtain an access token from the authentication endpoint.
# Get access token
curl --request POST \
--url "https://your-fineract-instance.com/fineract-provider/api/oauth/token" \
--header "Content-Type: application/x-www-form-urlencoded" \
--data "grant_type=password&username=mifos&password=password&client_id=community-app"
# Use token in subsequent requests
curl --request GET \
--url "https://your-fineract-instance.com/fineract-provider/api/v1/clients" \
--header "Authorization: Bearer YOUR_ACCESS_TOKEN" \
--header "Fineract-Platform-TenantId: default"Security Best Practices
- ✓Use HTTPS
Always use HTTPS to encrypt credentials in transit
- ✓Environment Variables
Store credentials in environment variables, not in code
- ✓Rotate Credentials
Regularly rotate passwords and API credentials
- ✓Least Privilege
Use role-based access to limit API permissions
Was this page helpful?