Authenticate with API Key
curl --request POST \
--url https://api.telemax.com.au/api/authentication/token/api-key \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data apiKey=your_api_key_hereimport requests
url = "https://api.telemax.com.au/api/authentication/token/api-key"
payload = { "apiKey": "your_api_key_here" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/x-www-form-urlencoded"
}
response = requests.post(url, data=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
Authorization: 'Bearer <token>',
'Content-Type': 'application/x-www-form-urlencoded'
},
body: new URLSearchParams({apiKey: 'your_api_key_here'})
};
fetch('https://api.telemax.com.au/api/authentication/token/api-key', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.telemax.com.au/api/authentication/token/api-key",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => "apiKey=your_api_key_here",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/x-www-form-urlencoded"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.telemax.com.au/api/authentication/token/api-key"
payload := strings.NewReader("apiKey=your_api_key_here")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/x-www-form-urlencoded")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.telemax.com.au/api/authentication/token/api-key")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/x-www-form-urlencoded")
.body("apiKey=your_api_key_here")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.telemax.com.au/api/authentication/token/api-key")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/x-www-form-urlencoded'
request.body = "apiKey=your_api_key_here"
response = http.request(request)
puts response.read_body{
"access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
"token_type": "Bearer",
"expires_in": 86399
}{
"type": "AUTHENTICATION",
"code": "TOKEN_EXPIRED",
"description": "The access token has expired. Request a new token using /api/authentication/token/user or /api/authentication/token/api-key.",
"requestId": "req_7f3a2b1c",
"docUrl": "https://docs.telemax.com.au/errors#token-expired"
}{
"type": "RATE_LIMIT",
"code": "RATE_LIMIT_EXCEEDED",
"description": "Too many requests. Wait 30 seconds before retrying.",
"requestId": "req_6d2f8b4a",
"docUrl": "https://docs.telemax.com.au/errors#rate-limit"
}{
"type": "SERVER_ERROR",
"code": "INTERNAL_ERROR",
"description": "An unexpected error occurred. Please try again or contact support with the requestId.",
"requestId": "req_1e5a3c7d",
"docUrl": "https://docs.telemax.com.au/errors#server-error"
}Authentication
API key token
Authenticate with an API key (GUID or legacy); receive a JWT.
POST
/
api
/
authentication
/
token
/
api-key
Authenticate with API Key
curl --request POST \
--url https://api.telemax.com.au/api/authentication/token/api-key \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data apiKey=your_api_key_hereimport requests
url = "https://api.telemax.com.au/api/authentication/token/api-key"
payload = { "apiKey": "your_api_key_here" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/x-www-form-urlencoded"
}
response = requests.post(url, data=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
Authorization: 'Bearer <token>',
'Content-Type': 'application/x-www-form-urlencoded'
},
body: new URLSearchParams({apiKey: 'your_api_key_here'})
};
fetch('https://api.telemax.com.au/api/authentication/token/api-key', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.telemax.com.au/api/authentication/token/api-key",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => "apiKey=your_api_key_here",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/x-www-form-urlencoded"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.telemax.com.au/api/authentication/token/api-key"
payload := strings.NewReader("apiKey=your_api_key_here")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/x-www-form-urlencoded")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.telemax.com.au/api/authentication/token/api-key")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/x-www-form-urlencoded")
.body("apiKey=your_api_key_here")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.telemax.com.au/api/authentication/token/api-key")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/x-www-form-urlencoded'
request.body = "apiKey=your_api_key_here"
response = http.request(request)
puts response.read_body{
"access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
"token_type": "Bearer",
"expires_in": 86399
}{
"type": "AUTHENTICATION",
"code": "TOKEN_EXPIRED",
"description": "The access token has expired. Request a new token using /api/authentication/token/user or /api/authentication/token/api-key.",
"requestId": "req_7f3a2b1c",
"docUrl": "https://docs.telemax.com.au/errors#token-expired"
}{
"type": "RATE_LIMIT",
"code": "RATE_LIMIT_EXCEEDED",
"description": "Too many requests. Wait 30 seconds before retrying.",
"requestId": "req_6d2f8b4a",
"docUrl": "https://docs.telemax.com.au/errors#rate-limit"
}{
"type": "SERVER_ERROR",
"code": "INTERNAL_ERROR",
"description": "An unexpected error occurred. Please try again or contact support with the requestId.",
"requestId": "req_1e5a3c7d",
"docUrl": "https://docs.telemax.com.au/errors#server-error"
}Overview
Authenticates using a GUID API key stored in Telemax, or a legacy non-GUID key resolved via the configured legacy API service. Returns a JWT including API key claims (Actions, Vehicles, DateFormat, etc.) when applicable.
A V2 version of this endpoint is available: API key token. New integrations should prefer V2.
Endpoint
POST /api/Authentication/token/api-key
Authentication
Not required.Request headers
| Header | Required | Description |
|---|---|---|
| Content-Type | Yes | application/x-www-form-urlencoded |
Request body (form)
string
required
API key string (GUID format or legacy format).
Example request body
apiKey=a3f1c2b4-5d6e-7890-abcd-ef1234567890
Response
200 OK — sameJwtTokenResponse shape as user login.
| Field | Type | Description |
|---|---|---|
| access_token | string | JWT |
| token_type | string | bearer |
| expires_in | number | Seconds |
Error responses
| Status | Meaning |
|---|---|
| 401 | GUID key not found or deleted |
| 400 | Legacy key could not be resolved, or no active API key row for resolved company |
curl -X POST "https://api.telemax.com.au/api/Authentication/token/api-key" \
-H "Content-Type: application/x-www-form-urlencoded" \
--data-urlencode "apiKey=a3f1c2b4-5d6e-7890-abcd-ef1234567890"
await fetch("https://api.telemax.com.au/api/Authentication/token/api-key", {
method: "POST",
headers: { "Content-Type": "application/x-www-form-urlencoded" },
body: new URLSearchParams({ apiKey: "a3f1c2b4-5d6e-7890-abcd-ef1234567890" }),
});
requests.post(
'https://api.telemax.com.au/api/Authentication/token/api-key',
data={'apiKey': 'a3f1c2b4-5d6e-7890-abcd-ef1234567890'},
)
Authorizations
JWT Bearer token obtained from POST /api/authentication/token/user or POST /api/authentication/token/api-key.
Lifetime: ~24 hours (86,399 seconds). Cache the token and reuse it. Re-authenticate 5 minutes before expiry.
Scoping:
- User tokens are scoped to a single company.
- API key tokens may restrict access to a vehicle allowlist and/or action set (see token claims).
No refresh endpoint — re-authenticate with your credentials when the token expires.
Headers
Standard and must keep it as it is.
Body
application/x-www-form-urlencoded
API key
Example:
"your_api_key_here"
Response
Successful response
JWT access token
Example:
"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."
Example:
"Bearer"
Token lifetime in seconds. Default is 86399.0 (≈24 hours). Cache and reuse this token until near expiry — do not request a new token per API call.
Example:
86399
Was this page helpful?