Skip to main content
POST

Body

Use this when your app has a backend server and can safely store a client secret. Exchange a one-time authorization code for tokens by sending client_secret.

client_id
string
required

OAuth2 client identifier.

Minimum string length: 1
client_secret
string
required

OAuth2 client secret for confidential server-side apps.

Minimum string length: 1
code
string
required

Authorization code returned from the authorize or confirm flow.

Minimum string length: 1
grant_type
enum<string>
required

Use code in JSON. Form-encoded requests also accept authorization_code.

Available options:
code
Minimum string length: 1
Example:

"code"

redirect_uri
string
required

Redirect URI used earlier in the login flow. Must match exactly.

Minimum string length: 1
Example:

"https://yourapp.com/callback"

Response

Tokens issued successfully

OAuth2 token response. All fields are always present. For client_credentials, refresh_token is empty and refresh_token_expires_in is 0.

access_token
string
required

OAuth2 access token used in the Authorization header.

expires_in
integer
required

Access token lifetime in seconds. 3600 for code and refresh_token grants; server-configured for client_credentials.

Example:

3600

refresh_token
string
required

Refresh token used to obtain a new access token later. Empty for client_credentials.

refresh_token_expires_in
integer
required

Refresh token lifetime in seconds. 0 for client_credentials.

Example:

31536000

scope
string
required

Space-separated scopes granted for this token.

Example:

"account:information order:execution"

token_type
enum<string>
required

Token type. Always Bearer.

Available options:
Bearer
Example:

"Bearer"