Skip to main content

Exchange a code or refresh token

POST 

/oauth/token

RFC 6749 4.1.3 and 6. Authenticate the client with HTTP Basic (preferred) or with client_id and client_secret in the body.

grant_type=authorization_code exchanges a code, with the redirect_uri it was issued for and the PKCE code_verifier. grant_type=refresh_token exchanges a refresh token, optionally for a narrower scope. Refresh tokens rotate: each is accepted once, and presenting one again (or a code again) revokes the whole authorisation, since a copy is in someone else's hands.

Errors are RFC 6749 5.2 bodies: invalid_request, invalid_client (401), invalid_grant, invalid_scope, unsupported_grant_type. Rate limited to 60 requests a minute. No key is sent.

Request​

Responses​

The tokens. Not to be cached.

Response Headers
    Cache-Control