CustomDomain™ docs
API referenceAgents

Exchange an authorization code or a refresh token for an access token

POST
/oauth/agent/token

grant_type=authorization_code (with the PKCE code_verifier) or grant_type=refresh_token. The access token is an ES256 JWT that lives 15 minutes and is verified locally against /.well-known/jwks.json; it carries the tenant, the application the grant is bound to, the grant, the scopes and aud. A refresh token rotates: every refresh returns a new one and retires the old, and presenting a retired one again revokes the whole grant (a client racing itself within ten seconds is only refused). Errors use the RFC 6749 envelope.

Request Body

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

curl -X POST "https://example.com/oauth/agent/token" \  -H "Content-Type: application/json" \  -d '{    "grant_type": "authorization_code",    "client_id": "string"  }'
{  "access_token": "string",  "token_type": "Bearer",  "expires_in": 0,  "refresh_token": "string",  "scope": "string"}
{  "error": "string",  "error_description": "string"}
{  "error": "string",  "error_description": "string"}