oAuth2

Exchange OAuth2 token

<Warning> This endpoint expects `application/x-www-form-urlencoded`. </Warning> <Warning> Try it will not return usable data for this route. It depends on a live OAuth2 authentication context outside the docs. </Warning> <Info> Get started with OAuth by reading [our guide](/oauth2/creating-an-application). </Info> <Info> Only the `authorization_code` grant type is supported. Authorization codes are one-time use and expire after 5 minutes. </Info>

PKCE is supported for both Private and Public applications but Public applications must send code_verifier and must not send client_secret.

Private applications must send client_secret.

Only S256 PKCE is supported.

post/oauth/token

Request body

grant_type'authorization_code' required

Only authorization_code is supported.

codestring required

One-time authorization code. Expires after 5 minutes.

redirect_uristring uri required

Must match the redirect URI used during authorization.

client_idstring required
client_secretstring

Required for private applications. Must not be sent by public applications.

code_verifierstring

Required for public applications and for any authorization code created with PKCE.

Response

OAuth2 access token exchange result.

access_tokenstring required
token_type'bearer' required
scopestring required

Space-delimited granted scopes.

Changes