OAuthTokenResponse
RFC 6749 token response. Not wrapped in ResponseData — the fields are snake_case
and sit at the top level, as the standard requires.
Send this as the X-Open-Api-Token header on resource endpoints.
uysot_at_5f2c1e8b9a4d7c3e6b0f2a1d8c4e7b3a9f6d2c5eAlways Bearer. Note that the Open API still reads the token from X-Open-Api-Token.
BearerAccess token lifetime in seconds.
3600The new refresh token. Rotated on every call — persist it, because the value you sent is no longer valid.
uysotrt_3a9f6d2c5e1b8f4a7d0c6e2b9f5a3d8c1e7b4f0aSpace-separated PERMISSION:SCOPE grants actually attached to the connection. May be
narrower than what you requested.
PERMISSION_OPEN_API_LEAD:READ PERMISSION_OPEN_API_CONTRACT:READHMAC secret for verifying webhook deliveries. Present only on a
grant_type=authorization_code response, and only when your application has a webhook
configuration — absent otherwise. This is the only time it is shown; store it, it is
not retrievable again from this endpoint.
3a9f6d2c5e1b8f4a7d0c6e2b9f5a3d8c7e1b4f0a9c6d2e5b8f3a1d7c0e6b9f2aSigning key for embedded (iframe) JWTs. Present only on a
grant_type=authorization_code response, and only when your application has an
embedded configuration — absent otherwise. Shown once, same as webhook_secret.
9f6d2c5e1b8f4a7d0c6e2b9f5a3d8c7e1b4f0a3c6d2e5b8f9a1d7c0e6b3f2a4d{
"access_token": "uysot_at_5f2c1e8b9a4d7c3e6b0f2a1d8c4e7b3a9f6d2c5e",
"token_type": "Bearer",
"expires_in": 3600,
"refresh_token": "uysotrt_3a9f6d2c5e1b8f4a7d0c6e2b9f5a3d8c1e7b4f0a",
"scope": "PERMISSION_OPEN_API_LEAD:READ PERMISSION_OPEN_API_CONTRACT:READ",
"webhook_secret": "3a9f6d2c5e1b8f4a7d0c6e2b9f5a3d8c7e1b4f0a9c6d2e5b8f3a1d7c0e6b9f2a",
"embedded_secret": "9f6d2c5e1b8f4a7d0c6e2b9f5a3d8c7e1b4f0a3c6d2e5b8f9a1d7c0e6b3f2a4d"
}