Exchange a code or refresh token
POST/oauth/token
RFC 6749 4.1.3 and 6. Authenticate the client with HTTP Basic
(preferred) or with client_id and client_secret in the body.
grant_type=authorization_code exchanges a code, with the
redirect_uri it was issued for and the PKCE code_verifier.
grant_type=refresh_token exchanges a refresh token, optionally for
a narrower scope. Refresh tokens rotate: each is accepted once, and
presenting one again (or a code again) revokes the whole
authorisation, since a copy is in someone else's hands.
Errors are RFC 6749 5.2 bodies: invalid_request, invalid_client
(401), invalid_grant, invalid_scope, unsupported_grant_type.
Rate limited to 60 requests a minute. No key is sent.
Request
Responses
- 200
- 400
- 401
- 429
The tokens. Not to be cached.
Response Headers
An RFC 6749 error.
Response Headers
Client authentication failed (invalid_client).
Response Headers
Basic realm="vehiso".
Too many requests. Code rate_limited; wait Retry-After seconds. On POST /theme-generations, also theme_generation_quota_exceeded, when the dealer's monthly theme generations are used up (no Retry-After).
Response Headers
This request's id. Quote it to support.
Requests allowed per minute for this key.
Requests left in the current minute.
Seconds to wait before retrying.