v1

latestOpenAPI 3.0.02026-07-263365201.7 KB
Authentication

Create a token

Retrieve a token

post/oauth/token

Request body

grant_type'authorization_code' | 'refresh_token' | 'client_credentials' required

The OAuth 2.0 grant type being used for the token request

codestring

The authorization code received from the authorization server (required for authorization_code grant type)

refresh_tokenstring

The refresh token used to obtain a new access token (required for refresh_token grant type)

client_idstring

The client identifier issued to the client during registration (required for public clients, when not authenticating via Basic Auth)

scopestring
code_verifierstring

PKCE code verifier used to verify the authorization request (required when PKCE was used in authorization request)

Example request

{
  "grant_type": "authorization_code",
  "code": "4/P7q7W91a-oMsCeLvIaQm6bTrgtp7",
  "refresh_token": "1B4a2e77838347a7E420ce178F2E7c6912E169246c",
  "client_id": "client_12345",
  "code_verifier": "dBjftJeZ4CVP-mB92K27uhbUJU1p1r_wW1gFWFOEjXk"
}

Response

Retrieve the quote details

access_tokenstring required

The access token to access the API endpoints

token_type'Bearer' required

The type of token issued, always 'Bearer'

expires_innumber required

The lifetime of the access token in seconds (60 minutes)

refresh_tokenstring required

The refresh token to create a new access_token

scopestring required

Space-delimited list of scopes granted on this token (RFC 6749).

Example response

{
  "access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJyb2xlcyI6WyJhZG1pbiJdLCJwYJ0bmVyIjoi...",
  "token_type": "Bearer",
  "expires_in": 3600,
  "refresh_token": "21cc84a3ad98736f4e5eddc88a1f4b58a29ae96206027c9b59d874cb2a7f7e02",
  "scope": "read:* write:*"
}