Issue Token Response
This API generates a content of a successful token response that the authorization server implementation returns to the client application.
Path parameters
A service ID.
Request body
The ticket issued from Authlete /auth/token API.
The subject (= unique identifier) of the authenticated user.
Additional claims that are added to the payload part of the JWT access token.
The representation of an access token that may be issued as a result of the Authlete API call.
The duration (in seconds) of the access token that may be issued as a result of the Authlete API call.
When this request parameter holds a positive integer, it is used as the duration of the access token in. In other cases, this request parameter is ignored.
The duration (in seconds) of the refresh token that may be issued as a result of the Authlete API call.
When this request parameter holds a positive integer, it is used as the duration of the refresh token in. In other cases, this request parameter is ignored.
Response
Token issued successfully
The code which represents the result of the API call.
A short message which explains the result of the API call.
The next action that the authorization server implementation should take.
The content that the authorization server implementation is to return to the client application. Its format is JSON.
The newly issued access token. This parameter is a non-null value only when the value of action parameter is OK.
The datetime at which the newly issued access token will expire. The value is represented in milliseconds since the Unix epoch (1970-01-01).
The duration of the newly issued access token in seconds.
The refresh token. This parameter is a non-null value only when action is OK and the service supports the refresh token flow. If refreshTokenKept is set to false, a new refresh token is issued and the old refresh token used in the refresh token flow is invalidated. On the contrary, if refreshTokenKept is set to true, the refresh token itself is not refreshed.
The datetime at which the newly issued refresh token will expire. The value is represented in milliseconds since the Unix epoch (1970-01-01).
The duration of the newly issued refresh token in seconds.
The client ID.
The client ID alias. If the client did not have an alias, this parameter is null.
The flag which indicates whether the client ID alias was used when the token request was made. true if the client ID alias was used when the token request was made.
The subject (= resource owner's ID) of the access token. Even if an access token has been issued by calling /api/auth/token API, this parameter is null if the flow of the token request was Client Credentials Flow (grant_type=client_credentials) because it means the access token is not associated with any specific end-user.
The scopes covered by the access token.
The newly issued access token in JWT format. If the authorization server is configured to issue JWT-based access tokens (= if the service's accessTokenSignAlg value is a non-null value), a JWT-based access token is issued along with the original random-string one.
The target resources of the access token being issued. See "Resource Indicators for OAuth 2.0" for details.
The entity ID of the client.
Flag which indicates whether the entity ID of the client was used when the request for the access token was made.
The scopes associated with the refresh token. May be null.
The location of the client's metadata document that was used to resolve client metadata.
This property is set when client metadata was retrieved via the OAuth Client ID Metadata Document (CIMD) mechanism.
Flag indicating whether a metadata document was used to resolve client metadata for this request.
When true, the client metadata was retrieved via the CIMD mechanism rather than from the Authlete database.