---
title: "Obtain a request token"
method: POST
path: "/oauth/request_token"
tags: ["OAuth"]
---

# Obtain a request token

`POST /oauth/request_token`

Obtain a request token. See section 6.1 of the OAuth v1.0a specification for more information. http://oauth.net/core/1.0a/#auth_step1

Note we do not return an oauth_token_secret in the response as we are using RSA signatures rather than PLAINTEXT authentication.

## Request body

- object
  - `oauth_consumer_key` string — The 25-character hexadecimal string that was obtained from Interactive Brokers during the OAuth consumer registration process.
  - `oauth_signature_method` string — The signature method used to sign the request. Currently only 'RSA-SHA256' is supported.
  - `oauth_signature` string — The signature for the request generated using the method specified in the oauth_signature_method parameter. See section 9 of the OAuth v1.0a specification for more details on signing requests.
  - `oauth_timestamp` string — Timestamp expressed in seconds since 1/1/1970 00:00:00 GMT. Must be a positive integer and greater than or equal to any timestamp used in previous requests.
  - `oauth_nonce` string — A random string uniquely generated for each request.
  - `oauth_callback` string — An absolute URL to which IB will redirect the user. This URL is provided by the consumer during registration. This parameter must be set to 'oob'.

## Response `200`

OAuth token

- object
  - `oauth_token` string

## Other responses

- `400` — Unsuccessfull response
- `401` — Unsuccessfull response
- `403` — Unsuccessfull response
- `408` — Unsuccessfull response

---

[API](https://skmtc.dev/interactivebrokers/apis/ibkr-3rd-party-web-api.md) · [All operations](https://skmtc.dev/interactivebrokers/apis/ibkr-3rd-party-web-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/interactivebrokers/ibkr-3rd-party-web-api/revisions/97f75703dba5/schema)
