Exchange an authorization code or a refresh token for an access token
grant_type=authorization_code (with the PKCE code_verifier) or grant_type=refresh_token. The access token is an ES256 JWT that lives 15 minutes and is verified locally against /.well-known/jwks.json; it carries the tenant, the application the grant is bound to, the grant, the scopes and aud. A refresh token rotates: every refresh returns a new one and retires the old, and presenting a retired one again revokes the whole grant (a client racing itself within ten seconds is only refused). Errors use the RFC 6749 envelope.
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
curl -X POST "https://example.com/oauth/agent/token" \ -H "Content-Type: application/json" \ -d '{ "grant_type": "authorization_code", "client_id": "string" }'{ "access_token": "string", "token_type": "Bearer", "expires_in": 0, "refresh_token": "string", "scope": "string"}{ "error": "string", "error_description": "string"}{ "error": "string", "error_description": "string"}