POST |
/oauth/token | Exchanges the code for the member's tokens, renews a login, or gives the app a token of its own (OAuth 2.1). |
| Information | Body | Response |
|---|---|---|
|
Called without a Bearer token. A client with a key sends its id and key in a Basic Authorization header (client_id:key in base64), which is what an OAuth client library does by itself, or as the form fields client_id and client_secret. A public client (no key) sends client_id alone. grant_type=authorization_code logs the member in with the code from GET /oauth/authorize: the reply has access_token, token_type (Bearer), expires_in (3600), scope (the client's rights) and refresh_token. The code works once, within two minutes, for the client and redirect_uri it was made for, and only with the code_verifier its challenge was made from. grant_type=refresh_token gives a new access token and a new refresh token; the old refresh token is dead at once. Renew when a call answers 401 with error="invalid_token", not before every call. Only the client that made the login can renew it. grant_type=client_credentials gives an access token for the app alone, good for GET /client only. Not for a public client. There is no grant_type=password (OAuth 2.1 removed it): it gets 400 unsupported_grant_type. A member's password is typed on myWebLog's login page only. A code or refresh token that is not valid gives 400 with error invalid_grant and an error_description meant for the app's user, in the language of Accept-Language. The reply follows the OAuth 2.0 standard, not the Problem Details form of the other endpoints. |
Form data (application/x-www-form-urlencoded), not JSON: grant_type: authorization_code, refresh_token or client_credentials. |
200 OK |