curl --request POST \
--url https://api.aries.com/v1/oauth2/token \
--header 'Content-Type: application/json' \
--data '
{
"client_id": "client_abc123xyz",
"client_secret": "secret_xyz789abc",
"code": "auth_code_abc123xyz789def456",
"grant_type": "code",
"redirect_uri": "https://yourapp.com/callback"
}
'{
"access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIn0.signature",
"expires_in": 3600,
"refresh_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJyZWYiOiIxMjM0NTY3ODkwIn0.signature",
"refresh_token_expires_in": 31536000,
"scope": "account:information order:execution",
"token_type": "Bearer"
}OAuth2 Token
Exchanges authorization codes for access and refresh tokens, or uses refresh tokens to obtain new access tokens. This endpoint supports multiple OAuth2 grant types including authorization_code and refresh_token flows.
Use Case: Obtain API access tokens after user authorization or refresh expired tokens to maintain continuous API access for applications.
curl --request POST \
--url https://api.aries.com/v1/oauth2/token \
--header 'Content-Type: application/json' \
--data '
{
"client_id": "client_abc123xyz",
"client_secret": "secret_xyz789abc",
"code": "auth_code_abc123xyz789def456",
"grant_type": "code",
"redirect_uri": "https://yourapp.com/callback"
}
'{
"access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIn0.signature",
"expires_in": 3600,
"refresh_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJyZWYiOiIxMjM0NTY3ODkwIn0.signature",
"refresh_token_expires_in": 31536000,
"scope": "account:information order:execution",
"token_type": "Bearer"
}Body
- Authorization Code
- PKCE
- Refresh Token
- Client Credentials
Use this when your app has a backend server and can safely store a client secret. Exchange a one-time authorization code for tokens by sending client_secret.
OAuth2 client identifier.
1OAuth2 client secret for confidential server-side apps.
1Authorization code returned from the authorize or confirm flow.
1Use code in JSON. Form-encoded requests also accept authorization_code.
code 1"code"
Redirect URI used earlier in the login flow. Must match exactly.
1"https://yourapp.com/callback"
Response
Tokens issued successfully
OAuth2 token response. All fields are always present. For client_credentials, refresh_token is empty and refresh_token_expires_in is 0.
OAuth2 access token used in the Authorization header.
Access token lifetime in seconds. 3600 for code and refresh_token grants; server-configured for client_credentials.
3600
Refresh token used to obtain a new access token later. Empty for client_credentials.
Refresh token lifetime in seconds. 0 for client_credentials.
31536000
Space-separated scopes granted for this token.
"account:information order:execution"
Token type. Always Bearer.
Bearer "Bearer"
Was this page helpful?