> ## Documentation Index
> Fetch the complete documentation index at: https://docs.bango.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Working with DVM APIs

> Use DVM API environments, OAuth2 authentication, API contracts, and Sandbox testing correctly.

Use these conventions when you connect to the Digital Vending Machine® (DVM™) APIs.

## Choose the correct environment

DVM separates Sandbox and production. Use credentials and endpoints for the same environment throughout a request flow.

| Purpose | Sandbox | Production |
| - | - | - |
| OAuth2 token service | `https://sandbox.auth.bango.com/oauth2/token` | `https://auth.bango.com/oauth2/token` |
| Products and Offers | `https://api.sandbox.bango.com` | `https://api.bango.com` |
| Entitlements — Reseller to DVM | `https://resale.api.sandbox.bango.com` | `https://resale.api.bango.com` |

Other API families can use endpoints documented for that API or supplied during onboarding.

<Warning>
  Do not mix Sandbox credentials, tokens, or identifiers with production endpoints.
</Warning>

## Authenticate API requests

OAuth2 Client Credentials is the default and recommended authentication method for enterprise DVM integrations.

To authenticate with OAuth2:

1. Request an access token from the token service for your environment using `grant_type=client_credentials` and the credentials supplied for your integration.
2. Cache the access token rather than requesting a new token for every API call.
3. Request a new token when the remaining validity is less than one minute.
4. Send the token in the request:

```http theme={null}
Authorization: Bearer <access_token>
```

Some existing integrations use Basic authentication where this has been configured. Use the authentication method supplied for your integration and supported by the API.

See [Set up authentication](/partner-management/setup-authentication) for how authentication fits into DVM onboarding.

## Follow the API contract

Use the current API reference for operation paths, request and response fields, headers, status behavior, and authentication supported by each API.

Request identifiers, idempotency behavior, and retry handling can vary by API and integration. Where an operation defines these behaviors, follow that API contract rather than applying a common rule across all DVM APIs.

Treat versioned paths and immutable technical identifiers exactly as published. Do not infer current behavior from legacy Bango API documentation.

Use the [API changelog](/API/changelog) to review published changes across the DVM APIs.

## Test in Sandbox

Validate your integration in Sandbox before production.

Use the [Testing overview](/testing/testing-overview) for the DVM testing path and certification stages.

For Reseller-to-DVM Entitlement API testing, you can use [mock response headers](/testing/mock-response-headers) to simulate defined Content Provider responses. `X-Magic-Number` is specific to that Entitlement API testing flow and is not a general DVM API header.

## Before production

Confirm that your integration:

* Uses production credentials and production endpoints.
* Caches and refreshes OAuth2 access tokens correctly where OAuth2 is configured.
* Follows the request headers and retry behavior documented for each API operation.
* Processes the notifications required for the integration.
* Has completed the testing and certification agreed with Bango.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.