Skip to main content
POST
Exchange a code or rotate a refresh token

Authorizations

Authorization
string
header
required

client_secret_basic: registered client identifier and secret.

Body

application/x-www-form-urlencoded
grant_type
enum<string>
required
Available options:
authorization_code,
refresh_token
Allowed value: "authorization_code"
code
string
required
Minimum string length: 1
redirect_uri
string<uri>
required
code_verifier
string
required
Minimum string length: 1
refresh_token
string
Minimum string length: 1
scope
string

Response

Successful response

access_token
string
required
Minimum string length: 1
expires_in
integer
required
expires_at
integer
required
token_type
enum<string>
required
Available options:
Bearer
scope
string
required
refresh_token
string
Minimum string length: 1
id_token
string
Minimum string length: 1