---
updatedAt: 2026-09-20T12:44:29.000Z
agentTools:
  projectIndex: https://docs.valmarpayments.com/llms.txt
---

# Basic Authentication

The authentication method used for this API

### Explanation

Basic Authentication is a method for an HTTP user agent to provide a username and password when making a request. The username and password is combined with a colon in between, and the string is then encoded using `base64` encoding. This resulting encoded string is then provided in subsequent HTTP request within the `Authorization` header. An example of this is provided below.

> 📘 Alternative: Bearer authentication
>
> The VMS API also accepts a JWT as a `Bearer` token, obtained from `POST /auth/login`. When MFA is required, complete the challenge with `POST /auth/login/challenge`. Refresh tokens with `POST /auth/login/refresh`. Bearer callers must additionally supply the `entityUuid` query parameter on authenticated endpoints; with Basic (API key) authentication the acting entity is resolved from the API key and `entityUuid` may be omitted.

### Example

Suppose that the username and password for a given user is: `valmarman2024` and `whoopie!23`.

These two values would be combined together with a colon in between, such as: `valmarman2024:whoopie!23`.

This string is then encoded using standard `base64` encoding.
The result of this would be: `dmFsbWFybWFuMjAyNDp3aG9vcGllITIz`.

This value is then used in the `Authorization` header of the HTTP request proceeded with `Basic`.

#### Code

```javascript
const credentials = "valmarman2024" + ":" + "whoopie!23";
const encodedValue = btoa(credentials); // = dmFsbWFybWFuMjAyNDp3aG9vcGllITIz

fetch("https://api.valmarpayments.com/...", {
  method: "POST",
  headers: {
    "Authorization": "Basic " + encodedValue,
    "Content-Type": "application/json"
  },
  body: JSON.stringify(bodyData)
});
```