Submit Your First API Call

This guide validates your end-to-end setup by obtaining an OAuth token and successfully calling a Galaxy API endpoint.

This step is a connectivity and authorization validation from your backend services. It does not replace workflow-level validation for trading, settlement, custody, staking, or reconciliation behaviors.

1. Before You Start

Make sure you already have:

  • API credentials (client_id, client_secret) for your target environment
  • Environment details (API base URL, auth domain, and auth server ID)
  • A terminal with curl available

If you still need setup details, start with Environments and Get Platform Access.

2. Choose Your Target Environment

Use UAT for first-time testing unless your implementation team advises differently.

Use Environments for the canonical environment matrix.

3. Request an Access Token

AUTH_DOMAIN="auth.api.uat.galaxy.com"
AUTH_SERVER_ID="ausy7o2fb3m86Kc8Z4x7"
CLIENT_ID="YOUR_CLIENT_ID"
CLIENT_SECRET="YOUR_CLIENT_SECRET"

curl -X POST "https://${AUTH_DOMAIN}/oauth2/${AUTH_SERVER_ID}/v1/token" \
 -H "Content-Type: application/x-www-form-urlencoded" \
 -d "grant_type=client_credentials" \
 -d "client_id=${CLIENT_ID}" \
 -d "client_secret=${CLIENT_SECRET}" \
 -d "scope=api:read"

Expected success response:

{
 "token_type": "Bearer",
 "expires_in": 3600,
 "access_token": "eyJraWQiOiJKV1..."
}

4. Call an API Endpoint

Use the token in the Authorization header:

TOKEN="YOUR_ACCESS_TOKEN"

curl "https://api.uat.galaxy.com/service-reference-g1/accounts" \
 -H "Authorization: Bearer ${TOKEN}"

If your token is valid and your client is authorized for the endpoint, you should receive a successful response body from the service.

5. One-Command Version

For quick verification, this script requests a token and performs an API call in one pass.

This example uses jq to parse the access token from the OAuth response:

AUTH_DOMAIN="auth.api.uat.galaxy.com"
AUTH_SERVER_ID="ausy7o2fb3m86Kc8Z4x7"
API_BASE_URL="https://api.uat.galaxy.com"
CLIENT_ID="YOUR_CLIENT_ID"
CLIENT_SECRET="YOUR_CLIENT_SECRET"

TOKEN=$(curl -s -X POST "https://${AUTH_DOMAIN}/oauth2/${AUTH_SERVER_ID}/v1/token" \
 -H "Content-Type: application/x-www-form-urlencoded" \
 -d "grant_type=client_credentials" \
 -d "client_id=${CLIENT_ID}" \
 -d "client_secret=${CLIENT_SECRET}" \
 -d "scope=api:read" | jq -r '.access_token')

curl -s "${API_BASE_URL}/service-reference-g1/accounts" \
 -H "Authorization: Bearer ${TOKEN}"

6. Troubleshooting

If the call fails, use the status code to narrow quickly:

  • 400 invalid_client: incorrect client credentials
  • 400 invalid_scope: scope not granted to your OAuth client
  • 401 Unauthorized: expired/invalid token, wrong auth endpoint, or wrong environment credentials
  • 403 Forbidden: your client is authenticated but not allowed to access this API
  • 429 Too Many Requests: back off and retry according to Retry-After

Also verify that:

  • Credentials and API base URL belong to the same environment
  • You are requesting only scopes assigned to your client
  • Your client is mapped to the correct consumer group(s)

7. What To Do Next

After your first successful request:

  1. Implement token caching and proactive refresh (refresh before expiry).
  2. Add retry/backoff handling for transient and rate-limit errors.
  3. Add idempotency support for all write operations.