For AI agents: the documentation index is at /llms.txt, and this page is available as Markdown at /api/auth/oauth-token.md.
Exchange a grant for tokens
POST/oauth/token
The token endpoint (RFC 6749 4.1.3 and 6), form encoded.
authorization_code consumes the code atomically, checks it was issued
to this client and this redirect_uri, and verifies PKCE. A code is
single-use: unknown, expired and already-redeemed are one answer, so a
caller cannot tell them apart.
refresh_token rotates: the presented token is consumed and the
response carries its replacement, minted with the stored audience and
scopes, so neither can widen on refresh. Refresh tokens are opaque and
single-use; replaying a consumed one revokes every token descended
from the same grant.
Request
Responses
- 200
- 400
- 401
Tokens issued
invalid_grant for a bad, expired, replayed or mismatched code or
PKCE verifier; unsupported_grant_type otherwise.
The client is unknown or disabled.