> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://en.docs.api.corpx.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://en.docs.api.corpx.com/_mcp/server.

# BaaS quick start

Welcome to the CorpX **BaaS** API documentation. This guide is for the **tenant / bank** that received a CorpX-issued credential. Calls go to `https://tenant.api.corpx.com`, without request signing.

If the credential came from internet banking, leave this page: [Internet banking quick start](/ib/guias/comece-aqui/primeiros-passos).

## 1. Obtaining Credentials

To start integrating, you will need access credentials. Contact our support team to receive:

* **Client ID**
* **Client Secret**
* **X-Tenant-Id** (Your Tenant identifier)

## 2. Authentication

Our API uses OAuth2 with the `client_credentials` flow. You must request an access token to make API calls.

### Endpoints

| Environment    | Token endpoint                            | API base                       |
| -------------- | ----------------------------------------- | ------------------------------ |
| **Production** | `https://auth.api.corpx.com/oauth2/token` | `https://tenant.api.corpx.com` |

### Token Request Example (Bash/cURL)

```bash
curl -X POST "https://auth.api.corpx.com/oauth2/token" \
     -H "Content-Type: application/x-www-form-urlencoded" \
     -u "$CLIENT_ID:$CLIENT_SECRET" \
     -d "grant_type=client_credentials&scope=api2/read+api2/write"
```

The response includes an `access_token` valid for **5 minutes** (`expires_in: 300`).

> **Reuse the token. Do not request a token per call.**
>
> The same `access_token` is valid for **every** call until it expires. Reusing
> it is **mandatory**: minting a new token on every request exhausts Cognito,
> slows your integration down, and can get token issuance refused.
>
> Cache the token on your side and only call `/oauth2/token` again when about
> 60 seconds remain on `expires_in` — or when the API answers `403` for an
> expired token. Details in the [authentication guide](/baas/guias/autenticacao/oauth2).

## 3. Making Your First Call

With the access token in hand, you can check the balance of an account, for example.

```bash
curl -X GET "https://tenant.api.corpx.com/v1/accounts/123456/balance" \
     -H "Authorization: Bearer YOUR_TOKEN" \
     -H "X-Tenant-Id: YOUR_TENANT_ID"
```

## 4. Next Steps

* Explore the [BaaS tenant guide](/baas/guias/comece-aqui/guia-do-integrador) for details on required headers and idempotency.
* Check the [API Reference](/baas/referencia) to see all available endpoints.
* Check the [Webhooks](/baas/guias/conta/webhooks) guide to receive real-time notifications.
* Use the [Transaction Timeline](/baas/guias/conta/timeline) to display the full
  lifecycle of any transaction inside your application.

## 5. Documentation for agents and LLMs

Read [Which documentation?](/) first — there are two audiences and two hosts. Filter the OpenAPI by `x-audience`.

* [llms.txt](https://docs.api.corpx.com/llms.txt) — router + index
* [llms-full.txt](https://docs.api.corpx.com/llms-full.txt) — concatenated guides
* [openapi.yaml](https://docs.api.corpx.com/openapi.yaml) — contract (paths, schemas, `x-audience`)

---

Need help? Reach out through your private Slack channel (request access during onboarding) or send an email to [api@corpx.com](mailto:api@corpx.com).