Skip to main content

OAuthTokenRequest

Form body of POST /v1/open-api/oauth/token. Which fields are required depends on grant_type: authorization_code needs code + redirect_uri, refresh_token needs refresh_token. client_id and client_secret are needed in both cases. client_id is always needed. client_secret is required for a confidential client; a public client (one registered through POST /v1/open-api/oauth/register) has none and sends code_verifier instead.

grant_typeOAuthGrantTyperequired

The OAuth grant being exercised on POST /v1/open-api/oauth/token.

Possible values: [authorization_code, refresh_token]

codestring

Authorization code from the consent redirect. authorization_code only — single-use, valid 10 minutes.

Example: uysot_code_9f86d081884c7d659a2feaa0c55ad015
redirect_uristring

Must match the redirect_uri the code was issued for, exactly. authorization_code only.

Example: https://acme.example/callback
refresh_tokenstring

The refresh token to exchange. refresh_token grant only.

Example: uysotrt_3a9f6d2c5e1b8f4a7d0c6e2b9f5a3d8c1e7b4f0a
client_idstringrequired

Your application's client identifier.

Example: uysot_app_9f86d081884c7d659a2f
client_secretstring

Your application's client secret. Backend only — never ship it to a browser or mobile app. Confidential clients only; a public client has no secret and authenticates the exchange with code_verifier.

Example: uysot_sec_3a9f6d2c5e1b8f4a7d0c6e2b9f5a3d8c
code_verifierstring

PKCE verifier (RFC 7636) — the original value whose SHA-256 you sent as code_challenge on /oauth/authorize. Required for public clients on the authorization_code grant, optional for confidential ones.

Example: uysot-mcp-test-verifier-c0c2e47ba5f0c26ff5b5a9c4e96fa4678511228a
OAuthTokenRequest
{
"grant_type": "authorization_code",
"code": "uysot_code_9f86d081884c7d659a2feaa0c55ad015",
"redirect_uri": "https://acme.example/callback",
"refresh_token": "uysotrt_3a9f6d2c5e1b8f4a7d0c6e2b9f5a3d8c1e7b4f0a",
"client_id": "uysot_app_9f86d081884c7d659a2f",
"client_secret": "uysot_sec_3a9f6d2c5e1b8f4a7d0c6e2b9f5a3d8c",
"code_verifier": "uysot-mcp-test-verifier-c0c2e47ba5f0c26ff5b5a9c4e96fa4678511228a"
}