---
title: "Token"
method: POST
path: "/v1/oauth/token"
tags: ["agent-auth"]
---

# Token

`POST /v1/oauth/token`

Exchange authorization_code + code_verifier, device_code, or refresh_token.

Send application/x-www-form-urlencoded. A refresh token is rotated on every
use; serialize refreshes and save the new token. Reuse revokes the connection.
Refresh may request the same or fewer approved scopes. A narrower access
token does not narrow the connection or its replacement refresh token.

## Response `200`

API-only access and rotating refresh token.

- object
  - `access_token` string, required
  - `refresh_token` string, required
  - `token_type` 'Bearer', required
  - `expires_in` integer, required
  - `scope` string, required — Granted permissions; may omit requested payments.

## Changes

- **2026-09-07** `8423a56e45c0` — 1 info
  - added the new optional request property `scope`
- **2026-09-07** `35a1cd3bea64` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/rmfg/apis/fastapi/changes/v1/oauth/token/post.md)

---

[API](https://skmtc.dev/rmfg/apis/fastapi.md) · [All operations](https://skmtc.dev/rmfg/apis/fastapi/llms.txt) · [OpenAPI document](https://skmtc.dev/rmfg/apis/fastapi/revisions/737527fc081e?raw)
