---
title: "Get Client Token"
method: POST
path: "/get-client-token"
tags: ["developers"]
---

# Get Client Token

`POST /get-client-token`

Gets Client Token

## Request body

- object
  - `op_configuration_endpoint` string, required — The openid configuration endpoint URL. If missing, then `op_host` must be defined.
  - `op_host` string — Deprecated in favor of `op_configuration_endpoint`. It will be removed in future version(s). Provide the URL of OpenID Provider (OP) in this field. If missing, then `op_configuration_endpoint` must be defined.
  - `op_discovery_path` string — Deprecated in favor of `op_configuration_endpoint`. It will be removed in future version(s). Provide path to the OpenID Connect Provider's discovery document in this field. For example, if it is 'https://example.com/.well-known/openid-configuration' then the path is blank. But if it is 'https://example.com/oxauth/.well-known/openid-configuration' then the path is '/oxauth'
  - `scope` string[]
  - `client_id` string, required
  - `client_secret` string, required
  - `authentication_method` string — if value is missed then basic authentication is used. Otherwise it's possible to set `private_key_jwt` value for Private Key authentication.
  - `algorithm` string — optional but is required if authentication_method=private_key_jwt. Valid values are none, HS256, HS384, HS512, RS256, RS384, RS512, ES256, ES384, ES512
  - `key_id` string — optional but is required if authentication_method=private_key_jwt. It has to be valid key id from key store.

## Response `200`

OK

- object
  - `scope` string[], required
  - `access_token` string, required
  - `expires_in` integer, required
  - `refresh_token` string, required

## Other responses

- `400` — Invalid parameters are provided to endpoint.
- `403` — Forbidden. Invalid access token provided in Authorization header.
- `500` — Internal error occured. Please check oxd-server.log file for details (usually located in /var/log/oxd-server/oxd-server.log).

---

[API](https://skmtc.net/gluufederation/apis/oxd-server.md) · [All operations](https://skmtc.net/gluufederation/apis/oxd-server/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/gluufederation/oxd-server/versions/33ca9e18c54b/schema)
