---
title: "Exchange access token"
method: PUT
path: "/v4/tokens/exchange/{token}"
tags: ["Authentication"]
---

# Exchange access token

`PUT /v4/tokens/exchange/{token}`

Exchanges the supplied access token for a fresh one with the same scopes and a renewed expiry. The original token is invalidated immediately on success. Use this to rotate long-lived integration tokens without re-authenticating.

## Path parameters

- `token` string, required

## Response `200`

Successful response

- AccessTokenResponse — Access-token metadata returned by `POST /v4/tokens`, `POST /v4/tokens/openid-connect/authorization-code-flow`, `GET /v4/tokens`, `GET /v4/tokens/{token}`, and `PUT /v4/tokens/exchange/{token}`. Pass `access_token` in the `Authorization` header (`Bearer ...`) on subsequent requests.
  - `access_token` string — Token string. Send as `Authorization: Bearer <access_token>` on subsequent requests, or as the `access_token` query parameter / `extole_token` cookie.
  - `client_id` string — Stable Extole identifier for the client (tenant) this token authenticates against.
  - `expires_in` integer — Seconds until this token expires. Once expired, requests using it return `401 invalid_access_token`; rotate via `PUT /v4/tokens/exchange/{token}` before expiry to keep long-lived integrations alive.
  - `identity_id` string — Stable Extole identifier for the identity (user, managed identity, or resource) that this token represents.
  - `person_id` string — Deprecated alias for `identity_id`. New integrations should use `identity_id`.
  - `scopes` string[] — Authorization scopes granted to this token. Determines which API operations the token may invoke.
  - `type` 'MANAGED' | 'RESOURCE' | 'USER' — Authentication shape backing the token. `USER` represents a human dashboard user, `MANAGED` an OAuth-style managed identity, and `RESOURCE` a scoped per-resource token.

## Other responses

- `400` — Bad Request
- `401` — Unauthorized
- `402` — Payment Required
- `403` — Forbidden
- `415` — Unsupported Media Type
- `429` — Too Many Requests

---

[API](https://skmtc.net/extole/apis/integration-api-server-to-extole.md) · [All operations](https://skmtc.net/extole/apis/integration-api-server-to-extole/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/extole/integration-api-server-to-extole/revisions/c16e62e66755/schema)
