agent-auth

Token

Exchange authorization_code + code_verifier, device_code, or refresh_token.

Send application/x-www-form-urlencoded. A refresh token is rotated on every use; serialize refreshes and save the new token. Reuse revokes the connection. Refresh may request the same or fewer approved scopes. A narrower access token does not narrow the connection or its replacement refresh token.

post/v1/oauth/token

Response

API-only access and rotating refresh token.

access_tokenstring required
refresh_tokenstring required
token_type'Bearer' required
expires_ininteger required
scopestring required

Granted permissions; may omit requested payments.

Changes

Changed in 2 of the 11 revisions of this API.2