OAuthTokenRequest
Form body of POST /v1/open-api/oauth/token. Which fields are required depends on
grant_type: authorization_code needs code + redirect_uri, refresh_token needs
refresh_token. client_id and client_secret are needed in both cases.
client_id is always needed. client_secret is required for a confidential client;
a public client (one registered through POST /v1/open-api/oauth/register) has none and
sends code_verifier instead.
The OAuth grant being exercised on POST /v1/open-api/oauth/token.
Possible values: [authorization_code, refresh_token]
Authorization code from the consent redirect. authorization_code only — single-use, valid 10 minutes.
uysot_code_9f86d081884c7d659a2feaa0c55ad015Must match the redirect_uri the code was issued for, exactly. authorization_code only.
https://acme.example/callbackThe refresh token to exchange. refresh_token grant only.
uysotrt_3a9f6d2c5e1b8f4a7d0c6e2b9f5a3d8c1e7b4f0aYour application's client identifier.
uysot_app_9f86d081884c7d659a2fYour application's client secret. Backend only — never ship it to a browser or mobile
app. Confidential clients only; a public client has no secret and authenticates the
exchange with code_verifier.
uysot_sec_3a9f6d2c5e1b8f4a7d0c6e2b9f5a3d8cPKCE verifier (RFC 7636) — the original value whose SHA-256 you sent as
code_challenge on /oauth/authorize. Required for public clients on the
authorization_code grant, optional for confidential ones.
uysot-mcp-test-verifier-c0c2e47ba5f0c26ff5b5a9c4e96fa4678511228a{
"grant_type": "authorization_code",
"code": "uysot_code_9f86d081884c7d659a2feaa0c55ad015",
"redirect_uri": "https://acme.example/callback",
"refresh_token": "uysotrt_3a9f6d2c5e1b8f4a7d0c6e2b9f5a3d8c1e7b4f0a",
"client_id": "uysot_app_9f86d081884c7d659a2f",
"client_secret": "uysot_sec_3a9f6d2c5e1b8f4a7d0c6e2b9f5a3d8c",
"code_verifier": "uysot-mcp-test-verifier-c0c2e47ba5f0c26ff5b5a9c4e96fa4678511228a"
}