OAuth 2.1 token endpoint

Exchanges an authorization code (+ PKCE verifier) for an access + refresh token, or refreshes an existing token. Rate-limited to 30 req/min/IP. RFC 8707 resource required.

POST/api/auth/oauth2/token

Request Body

application/x-www-form-urlencoded

curl -X POST "https://your-instance/api/auth/oauth2/token" \  -H "Content-Type: application/x-www-form-urlencoded" \  -d 'grant_type=authorization_code&client_id=string&resource=http%3A%2F%2Fexample.com'
{
  "access_token": "string",
  "token_type": "Bearer",
  "expires_in": 0,
  "expires_at": 0,
  "refresh_token": "string",
  "id_token": "string",
  "scope": "string"
}
{
  "error": "string",
  "error_description": "string"
}
{
  "error": "string",
  "error_description": "string"
}
{
  "error": "string",
  "error_description": "string"
}
{
  "error": "temporarily_unavailable",
  "error_description": "string"
}