> For the complete documentation index, see [llms.txt](https://developers.citrusad.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developers.citrusad.com/partner/reference/user-key-authentication.md).

# User key token

{% hint style="info" %}
Epsilon Retail Media's documentation is now centralized with our knowledgebase!

For up to date guides, please view [this page](https://help.citrusad.com/retail-media-interface/partner/partner-api-authentication/user-key-authentication) in the new Partner APIs space of our documentation.
{% endhint %}

## Requesting tokens

To receive your required access token, make a request to the `/user-key-token` endpoint by adding the following parameters using the `application/x-www-form-urlencoded` format with a character encoding of UTF-8 in the HTTP request body.

```http
POST https://auth.<env>.citrusad.com/v2/user-key-token
Content-Type: application/x-www-form-urlencoded
user_key=<USER_KEY>
```

You will receive a response with an `accessToken`,`expiresIn`, and `tokenType`.

```json
{
    "accessToken": "ACCESS_TOKEN",
    "expiresIn": 84000,
    "tokenType": "Bearer"
}
```

{% hint style="info" %}
Your **access** token is used to access the Epsilon Retail Media API.
{% endhint %}

## Refresh token

When your access token expires, you will receive an invalid token error from the campaign API. In this case, you will make a request to the `/token` endpoint with your refresh token as illustrated in the diagram below:

<figure><img src="https://110176934-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyPijakfWdNW5OjxjMGoY%2Fuploads%2Fgit-blob-4c11a28eb55016394366c69497940023a2df8f0f%2FAuthentication_refresh_flow.png?alt=media" alt="Authentication refresh flow.png" width="100%"><figcaption></figcaption></figure>

Usually, a user will only need a new access token when the previous one expires, or when they gain or lose access to resources that are attached to their claims. It is bad practice to call the endpoint to get a new access token for every request to our API.
