Skip to main content
POST
Create a token

Authorizations

Authorization
string
header
required

Basic authentication header of the form Basic <encoded-value>, where <encoded-value> is the base64-encoded string username:password.

Body

application/json

The token request

grant_type
enum<string>
required

The OAuth 2.0 grant type being used for the token request

Available options:
authorization_code,
refresh_token,
client_credentials
Example:

"authorization_code"

code
string

The authorization code received from the authorization server (required for authorization_code grant type)

Example:

"da5cece172d6a8f65f91f90b3fe65b1e"

refresh_token
string

The refresh token used to obtain a new access token (required for refresh_token grant type)

Example:

"ddbc4f94dbb2d19e23a81327042b35fc"

client_id
string

The client identifier issued to the client during registration (required for public clients, when not authenticating via Basic Auth)

Example:

"client_12345"

scope
string
code_verifier
string

PKCE code verifier used to verify the authorization request (required when PKCE was used in authorization request)

Example:

"dBjftJeZ4CVP-mB92K27uhbUJU1p1r_wW1gFWFOEjXk"

Response

The issued access token and refresh token

access_token
string
required

The access token to access the API endpoints

Example:

"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJyb2xlcyI6WyJhZG1pbiJdLCJwYJ0bmVyIjoi..."

token_type
enum<string>
required

The type of token issued, always 'Bearer'

Available options:
Bearer
Example:

"Bearer"

expires_in
number
required

The lifetime of the access token in seconds (60 minutes)

Example:

3600

refresh_token
string
required

The refresh token to create a new access_token

Example:

"ddbc4f94dbb2d19e23a81327042b35fc"

scope
string
required

Space-delimited list of scopes granted on this token (RFC 6749).

Example:

"read:* write:*"