POST |
/oauth/token | Exchanges a token for an access token that is valid for one hour (OAuth 2.0 client credentials). |
| Information | Body | Response |
|---|---|---|
|
Called without a Bearer token. The client id and secret are sent in a Basic Authorization header (client_id:client_secret in base64, which is what OAuth 2.0 libraries do), or as the form fields client_id and client_secret. The client id is the token's "Client ID" on the website; the client secret is the token. The access token has the token's rights, is limited to the same IP addresses, counts against the same rate limit and stops working when the token is deleted. Fetching it counts as one call. The reply follows the OAuth 2.0 standard: "access_token", "token_type" ("Bearer"), "expires_in" (3600) and, for information, "scope" (the rights, as "users:rw transactions:r"). An error is {"error": ..., "error_description": ...} with 400 (invalid_request, unsupported_grant_type) or 401 (invalid_client: wrong id or secret, deleted token, IP address not allowed, or the owner is no longer an administrator). 429 and 500 are the API's usual replies. |
Form data (application/x-www-form-urlencoded), not JSON: grant_type: must be client_credentials. |
200 OK |