Skip to main content

For AI agents: the documentation index is at /llms.txt, and this page is available as Markdown at /api/auth/oauth-token.md.

Exchange a grant for tokens

POST 

/oauth/token

The token endpoint (RFC 6749 4.1.3 and 6), form encoded.

authorization_code consumes the code atomically, checks it was issued to this client and this redirect_uri, and verifies PKCE. A code is single-use: unknown, expired and already-redeemed are one answer, so a caller cannot tell them apart.

refresh_token rotates: the presented token is consumed and the response carries its replacement, minted with the stored audience and scopes, so neither can widen on refresh. Refresh tokens are opaque and single-use; replaying a consumed one revokes every token descended from the same grant.

Request​

Responses​

Tokens issued