Token Endpoint

The App's Server fetch tokens.

NOTE

  1. Content-Type MUST be application/x-www-form-urlencoded;
  2. The App MUST authenticated itself, via either Secret Basic or Secret Post method;
  3. access_token is Json Web Token;
  4. When the grant type is client_credentials, the sub payload claim of access_token is client:{client_id};
  5. Content-Type of the response is application/json;charset=UTF-8;
  6. For explanation of errors, please refer to Section 5.2 of RFC6749.

Example

Authorization Code Grant Type

grant_type: authorization_code
code: yfz_7OBH9Eektoyb70GKcRTqmnshAQuolLqNzr63Vgs.z4591d8Yg9m7-KcygngZ9kO38rpGvdde7jjHKhLDM08
redirect_uri: 'http://localhost:3846/callback'

Refresh Token Grant Type

grant_type: refresh_token
refresh_token: YU7w7bnP9dfp5-TBKTXRaPPT0BvkgSag5xHyGVVMo80.UL6_E30Zxk1F5GwQT2VzQLKr19c1HobG9MkdBDdi4LM

Client Credentials Grant Type

grant_type: client_credentials
scope: api.users:write
audience: openapi
Language
Credentials
Basic
base64
:
Click Try It! to start a request and see the response here!