Obtain an access token
Make aPOST request to the Token URL provided at onboarding.
Recommended: HTTP Basic Auth for credentials, with a form body that includes grant_type. scope is optional and only needed if your tenant’s API gateway is configured to require a specific scope.
billreview:<CustomerScope> (for example, billreview:write):
scope is optional by default. If your onboarding instructions include a scope, use that value.Alternate: credentials in the body
Some HTTP clients prefer putting credentials in the form body instead of Basic Auth. If your onboarding instructions do not include a scope, omit the&scope=... line.
Token response
Using the token on API calls
Every BillReview API request requires both headers:403.
Compression
Request bodies may be sent as plain JSON or gzip-compressed JSON. Gzip is recommended for large payloads (many service lines) to reduce bandwidth and latency. Plain JSON (simplest — works in Postman and all HTTP clients):Content-Encoding: gzip is present, the body must be the gzip-compressed bytes of a valid JSON object. Content-Type remains application/json regardless — it describes the underlying data format, not the transport encoding.
Responses from the API are always gzip-compressed. Most HTTP clients (including Postman, curl with --compressed, and all common HTTP libraries) decompress responses automatically when they send Accept-Encoding: gzip.
Maximum body size: 10 MB.Exception:
POST /v1/facility accepts plain JSON only — do not gzip that endpoint.