oauth

Exchange an authorization code or refresh token for an access token

Changed on

The only grant flow enabled is authorization_code, and PKCE is required with the S256 challenge method. Refresh tokens are issued.

post/oauth/token

Request

  • Base URL: https://e621.net
  • URL: https://e621.net/oauth/token
  • Auth: one of:
    • none
    • HTTP basic
    • API key in query parameter login and API key in query parameter api_key

Request body

grant_type'authorization_code' | 'refresh_token' required

The grant type. authorization_code is the only enabled flow, and refresh_token may be used to renew a token.

client_idstring required

The application's client identifier

client_secretstring

The application's client secret, for confidential clients

codestring

The authorization code, for grant_type=authorization_code

redirect_uristring

The redirect URI used in the authorization request

code_verifierstring

The PKCE code verifier. Required, since PKCE is enforced.

refresh_tokenstring

The refresh token, for grant_type=refresh_token

Response

The issued token

access_tokenstring required

The issued access token

token_typestring required

The token type, Bearer

expires_ininteger required

The token lifetime in seconds

refresh_tokenstring

The refresh token, when one was issued

scopestring

The granted scopes, space separated

created_atinteger required

When the token was issued, as a Unix timestamp

id_tokenstring

The ID token, when the openid scope was granted

Changes