---
title: "Changes to Exchange a token grant"
method: POST
path: "/oauth2/token"
---

# Changes to Exchange a token grant

`POST /oauth2/token`

> Every recorded change to this endpoint, newest first.

## Timeline

Changed in 3 of 7 revisions.

- **2026-03-18** `e271d0e41f6d` — 2 breaking, 3 info
- **2026-03-06** `61b60b0c0d52` — 4 info
- **2026-02-03** `fc0a40f3b859` — 2 breaking, 4 warning, 3 info

## Changes

- **2026-03-18** `e271d0e41f6d` — 2 breaking, 3 info
  - request body became required
  - removed the media type `application/json` from the request body
  - api operation id `post_oauth2_token` removed and replaced with `postOauth2Token`
  - added the new optional `header` request parameter `XF-Api-User` to all path's operations
  - added the new optional `query` request parameter `api_bypass_permissions` to all path's operations
- **2026-03-06** `61b60b0c0d52` — 4 info
  - api tag `OAuth2` added
  - api tag `oauth2` removed
  - added optional request body
  - added the media type `application/json` for the response with the status `200`
- **2026-02-03** `fc0a40f3b859` — 2 breaking, 4 warning, 3 info
  - removed the request body
  - removed the media type `application/json` for the response with the status `200`
  - the optional response header `XF-Latest-Api-Version` removed for the status `200`
  - the optional response header `XF-Request-User` removed for the status `200`
  - the optional response header `XF-Request-User-Extras` removed for the status `200`
  - the optional response header `XF-Used-Api-Version` removed for the status `200`
  - api operation id `postOauth2Token` removed and replaced with `post_oauth2_token`
  - api tag `oauth2` added
  - api tag `OAuth2` removed

---

[Operation](https://skmtc.dev/xenforo-ltd/apis/xenforo-api/docs/oauth2/token/post.md) · [API](https://skmtc.dev/xenforo-ltd/apis/xenforo-api.md) · [Page](https://skmtc.dev/xenforo-ltd/apis/xenforo-api/changes/oauth2/token/post)
