Submit Your First API Call
This guide validates your end-to-end setup by obtaining an OAuth token and successfully calling a Galaxy API endpoint.
This step is a connectivity and authorization validation from your backend services. It does not replace workflow-level validation for trading, settlement, custody, staking, or reconciliation behaviors.
1. Before You Start
Make sure you already have:
- API credentials (
client_id,client_secret) for your target environment - Environment details (API base URL, auth domain, and auth server ID)
- A terminal with
curlavailable
If you still need setup details, start with Environments and Get Platform Access.
2. Choose Your Target Environment
Use UAT for first-time testing unless your implementation team advises differently.
Use Environments for the canonical environment matrix.
3. Request an Access Token
AUTH_DOMAIN="auth.api.uat.galaxy.com"
AUTH_SERVER_ID="ausy7o2fb3m86Kc8Z4x7"
CLIENT_ID="YOUR_CLIENT_ID"
CLIENT_SECRET="YOUR_CLIENT_SECRET"
curl -X POST "https://${AUTH_DOMAIN}/oauth2/${AUTH_SERVER_ID}/v1/token" \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "grant_type=client_credentials" \
-d "client_id=${CLIENT_ID}" \
-d "client_secret=${CLIENT_SECRET}" \
-d "scope=api:read"
Expected success response:
{
"token_type": "Bearer",
"expires_in": 3600,
"access_token": "eyJraWQiOiJKV1..."
}
4. Call an API Endpoint
Use the token in the Authorization header:
TOKEN="YOUR_ACCESS_TOKEN"
curl "https://api.uat.galaxy.com/service-reference-g1/accounts" \
-H "Authorization: Bearer ${TOKEN}"
If your token is valid and your client is authorized for the endpoint, you should receive a successful response body from the service.
5. One-Command Version
For quick verification, this script requests a token and performs an API call in one pass.
This example uses jq to parse the access token from the OAuth response:
AUTH_DOMAIN="auth.api.uat.galaxy.com"
AUTH_SERVER_ID="ausy7o2fb3m86Kc8Z4x7"
API_BASE_URL="https://api.uat.galaxy.com"
CLIENT_ID="YOUR_CLIENT_ID"
CLIENT_SECRET="YOUR_CLIENT_SECRET"
TOKEN=$(curl -s -X POST "https://${AUTH_DOMAIN}/oauth2/${AUTH_SERVER_ID}/v1/token" \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "grant_type=client_credentials" \
-d "client_id=${CLIENT_ID}" \
-d "client_secret=${CLIENT_SECRET}" \
-d "scope=api:read" | jq -r '.access_token')
curl -s "${API_BASE_URL}/service-reference-g1/accounts" \
-H "Authorization: Bearer ${TOKEN}"
6. Troubleshooting
If the call fails, use the status code to narrow quickly:
400 invalid_client: incorrect client credentials400 invalid_scope: scope not granted to your OAuth client401 Unauthorized: expired/invalid token, wrong auth endpoint, or wrong environment credentials403 Forbidden: your client is authenticated but not allowed to access this API429 Too Many Requests: back off and retry according toRetry-After
Also verify that:
- Credentials and API base URL belong to the same environment
- You are requesting only scopes assigned to your client
- Your client is mapped to the correct consumer group(s)
7. What To Do Next
After your first successful request:
- Implement token caching and proactive refresh (refresh before expiry).
- Add retry/backoff handling for transient and rate-limit errors.
- Add idempotency support for all write operations.