Admin Authentication
The Admin API uses a separate JWT from the merchant API. Obtain an admin token by calling the admin login endpoint:Admin tokens are distinct from merchant tokens. A merchant Bearer token will not grant access to admin routes.
Role-Based Access Control (RBAC)
Admin users are assigned roles, and each role contains a set of permissions. The platform enforces RBAC on every admin endpoint — if the authenticated user’s role does not include the required permission, the API returns403 FORBIDDEN.
Manage roles and permissions via the User Management endpoints.