v1
latestOpenAPI 3.1.0CC-BY-NC-SA-4.02026-07-2413803.8 MBGenerate tokens
Exchange the authorization code you received from the Authorize endpoint for an 'access token' API credential, with which you can communicate with the Mollie API on behalf of the consenting merchant.
This endpoint can only be accessed using OAuth client credentials.
🔑 Access with
Basic authentication
Headers
The OAuth client ID and client secret as basic access credentials.
Pseudo code: "Basic " + toBase64(client_id + ":" + client_secret)
For example: Basic QWxhZGRpbjpvcGVuIHNlc2FtZQ==
This header value must match the type of the request body you send, if there is a request body. For example, if you send the request body as JSON, this header must be set to application/json, and if you send it as form encoded you must set this header to application/x-www-form-urlencoded.
Request body
Example request
{
"grant_type": "authorization_code",
"code": "auth_...",
"refresh_token": "refresh_...",
"redirect_uri": "https://example.com/redirect"
}Response
The newly generated access token and refresh token.
Example response
{
"access_token": "access_...",
"refresh_token": "refresh_...",
"expires_in": 3600,
"token_type": "bearer",
"scope": "payments.read"
}