Skip to main content

Exchange Token

POST 

/v1/open-api/oauth/token

The OAuth 2.0 token endpoint (RFC 6749). A confidential client must call it from your backend only — it carries the client_secret.

Two grants are supported:

  • authorization_code — exchanges the code returned to your redirect_uri after the company approved your app. A code is single-use and valid for 10 minutes; the redirect_uri must be the exact one the code was issued for.
  • refresh_token — exchanges a refresh token for a fresh access token. Refresh tokens rotate: the response carries a new refresh_token and the one you sent stops working. Access tokens issued earlier keep working until they expire on their own.

The resulting access_token is sent as X-Open-Api-Token on resource endpoints — not as Authorization: Bearer, despite token_type.

The request body is application/x-www-form-urlencoded, and the response is the plain RFC 6749 object — this endpoint and /v1/open-api/oauth/revoke are the only ones not wrapped in the standard ResponseData envelope.

PKCE (RFC 7636). A public client — one registered with no client_secret, which is what POST /v1/open-api/oauth/register always produces — must send code_verifier, the original value of the code_challenge it passed to /oauth/authorize. For a confidential client PKCE is optional and client_secret is what authenticates it.

Requires no token — a confidential client authenticates with client_id + client_secret, a public client with client_id + code_verifier.

Request​

Responses​

A new access token (and a rotated refresh token).