Exchange Token
POST/v1/open-api/oauth/token
The OAuth 2.0 token endpoint (RFC 6749). A confidential client must call it from your
backend only — it carries the client_secret.
Two grants are supported:
authorization_code— exchanges thecodereturned to yourredirect_uriafter the company approved your app. A code is single-use and valid for 10 minutes; theredirect_urimust be the exact one the code was issued for.refresh_token— exchanges a refresh token for a fresh access token. Refresh tokens rotate: the response carries a newrefresh_tokenand the one you sent stops working. Access tokens issued earlier keep working until they expire on their own.
The resulting access_token is sent as X-Open-Api-Token on resource endpoints — not as
Authorization: Bearer, despite token_type.
The request body is application/x-www-form-urlencoded, and the response is the plain
RFC 6749 object — this endpoint and /v1/open-api/oauth/revoke are the only ones not
wrapped in the standard ResponseData envelope.
PKCE (RFC 7636). A public client — one registered with no client_secret, which is
what POST /v1/open-api/oauth/register always produces — must send code_verifier, the
original value of the code_challenge it passed to /oauth/authorize. For a
confidential client PKCE is optional and client_secret is what authenticates it.
Requires no token — a confidential client authenticates with
client_id + client_secret, a public client with client_id + code_verifier.
Request
Responses
- 200
- 400
- 401
- 429
A new access token (and a rotated refresh token).
Invalid request, grant, scope or grant_type (400). Branch on error.messageCode:
6907 invalid request, 6906 invalid grant (expired/used code, mismatched
redirect_uri, invalid or expired refresh token, failed code_verifier,
disconnected company), 6904 invalid scope, 6909 unsupported grant_type.
The body is the RFC 6749 §5.2 error object, not the standard envelope.
Unknown client_id, or a wrong or missing client_secret (401, error
invalid_client, message_code 6905).
Too many OAuth requests from this client or IP (429). Carries Retry-After and
the X-RateLimit-* headers; the body is the bare {"error":"too_many_requests"}.