---
title: "OAuth2 token exchange."
method: POST
path: "/oauth2/tokens"
tags: ["Enterprise"]
---

# OAuth2 token exchange.

`POST /oauth2/tokens`

## Response `200`

OK

- Oauth2Token
  - `access_token` string — AccessToken is the token that authorizes and authenticates the requests.
  - `expires_in` integer — ExpiresIn is the OAuth2 wire format "expires_in" field, which specifies how many seconds later the token expires, relative to an unknown time base approximately around "now". It is the application's responsibility to populate `Expiry` from `ExpiresIn` when required.
  - `expiry` string — Expiry is the optional expiration time of the access token. If zero, [TokenSource] implementations will reuse the same token forever and RefreshToken or equivalent mechanisms for that TokenSource will not be used.
  - `refresh_token` string — RefreshToken is a token that's used by the application (as opposed to the user) to refresh the access token if it expires.
  - `token_type` string — TokenType is the type of token. The Type method returns either this or "Bearer", the default.

---

[API](https://skmtc.net/coder/apis/coder-api.md) · [All operations](https://skmtc.net/coder/apis/coder-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/coder/coder-api/revisions/50a77af44008/schema)
