## Authentication Workflow

The typical flow for two-legged OAuth processing involves the following activities:

1. An OAuth client initiates a request with an authorization server and receives an access token.
2. The OAuth client uses the access token to access protected resources on the resource server.

## Resource Interaction

> 📘
>
> ### Access Token Lifespan
>
> Access tokens have a 15 minute lifespan.

When interacting with the Interchecks Payments API and a `401` HTTP Status Code is returned, its likely the access token has expired. Re-authenticate using the `oauth2/token` endpoint to retrieve a new access token.
