---
title: "First API Call"
description: "Submit Your First API Call"
url: "https://docs.api.galaxy.com/guides/galaxyone/first-api-call"
image: "https://docs.api.galaxy.com/_og/d/c_Ocean.takumi,title_First+API+Call,description_Submit+Your+First+API+Call,props_eyJ0aGVtZSI6eyJtb2RlIjoiZGFyayIsImNvbG9ycyI6eyJwcmltYXJ5IjoiI2ZmNWExZiJ9fX0,p_Ii9ndWlkZXMvZ2FsYXh5b25lL2ZpcnN0LWFwaS1jYWxsIg,s_acYj5Bwv8KOmXT2u.png"
---

Submit Your First API Call

This guide validates your end-to-end setup by obtaining an OAuth token and successfully calling a Galaxy API endpoint.

This step is a connectivity and authorization validation from your backend services. It does not replace workflow-level validation for trading, settlement, custody, staking, or reconciliation behaviors.

## [1\. Before You Start](#_1-before-you-start)

Make sure you already have:

-   API credentials (`client_id`, `client_secret`) for your target environment
-   Environment details (API base URL, auth domain, and auth server ID)
-   A terminal with `curl` available

If you still need setup details, start with [Environments](https://docs.api.galaxy.com/guides/galaxyone/environments.md) and [Get Platform Access](https://docs.api.galaxy.com/guides/galaxyone/platform-access.md).

## [2\. Choose Your Target Environment](#_2-choose-your-target-environment)

Use UAT for first-time testing unless your implementation team advises differently.

Use [Environments](https://docs.api.galaxy.com/guides/galaxyone/environments.md) for the canonical environment matrix.

## [3\. Request an Access Token](#_3-request-an-access-token)

```bash
AUTH_DOMAIN="auth.api.uat.galaxy.com"
AUTH_SERVER_ID="ausy7o2fb3m86Kc8Z4x7"
CLIENT_ID="YOUR_CLIENT_ID"
CLIENT_SECRET="YOUR_CLIENT_SECRET"

curl -X POST "https://${AUTH_DOMAIN}/oauth2/${AUTH_SERVER_ID}/v1/token" \
 -H "Content-Type: application/x-www-form-urlencoded" \
 -d "grant_type=client_credentials" \
 -d "client_id=${CLIENT_ID}" \
 -d "client_secret=${CLIENT_SECRET}" \
 -d "scope=api:read"
```

Expected success response:

```json
{
 "token_type": "Bearer",
 "expires_in": 3600,
 "access_token": "eyJraWQiOiJKV1..."
}
```

## [4\. Call an API Endpoint](#_4-call-an-api-endpoint)

Use the token in the `Authorization` header:

```bash
TOKEN="YOUR_ACCESS_TOKEN"

curl "https://api.uat.galaxy.com/service-reference-g1/accounts" \
 -H "Authorization: Bearer ${TOKEN}"
```

If your token is valid and your client is authorized for the endpoint, you should receive a successful response body from the service.

## [5\. One-Command Version](#_5-one-command-version)

For quick verification, this script requests a token and performs an API call in one pass.

This example uses `jq` to parse the access token from the OAuth response:

```bash
AUTH_DOMAIN="auth.api.uat.galaxy.com"
AUTH_SERVER_ID="ausy7o2fb3m86Kc8Z4x7"
API_BASE_URL="https://api.uat.galaxy.com"
CLIENT_ID="YOUR_CLIENT_ID"
CLIENT_SECRET="YOUR_CLIENT_SECRET"

TOKEN=$(curl -s -X POST "https://${AUTH_DOMAIN}/oauth2/${AUTH_SERVER_ID}/v1/token" \
 -H "Content-Type: application/x-www-form-urlencoded" \
 -d "grant_type=client_credentials" \
 -d "client_id=${CLIENT_ID}" \
 -d "client_secret=${CLIENT_SECRET}" \
 -d "scope=api:read" | jq -r '.access_token')

curl -s "${API_BASE_URL}/service-reference-g1/accounts" \
 -H "Authorization: Bearer ${TOKEN}"
```

## [6\. Troubleshooting](#_6-troubleshooting)

If the call fails, use the status code to narrow quickly:

-   `400 invalid_client`: incorrect client credentials
-   `400 invalid_scope`: scope not granted to your OAuth client
-   `401 Unauthorized`: expired/invalid token, wrong auth endpoint, or wrong environment credentials
-   `403 Forbidden`: your client is authenticated but not allowed to access this API
-   `429 Too Many Requests`: back off and retry according to `Retry-After`

Also verify that:

-   Credentials and API base URL belong to the same environment
-   You are requesting only scopes assigned to your client
-   Your client is mapped to the correct consumer group(s)

## [7\. What To Do Next](#_7-what-to-do-next)

After your first successful request:

1.  Implement token caching and proactive refresh (refresh before expiry).
2.  Add retry/backoff handling for transient and rate-limit errors.
3.  Add idempotency support for all write operations.