Exchange a code or rotate a refresh token
curl --request POST \
--url https://api.sharedgraph.com/api/auth/oauth2/token \
--header 'Authorization: Basic <encoded-value>' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data grant_type=authorization_code \
--data 'code=<string>' \
--data 'redirect_uri=<string>' \
--data 'code_verifier=<string>' \
--data 'refresh_token=<string>' \
--data 'scope=<string>'const options = {
method: 'POST',
headers: {
Authorization: 'Basic <encoded-value>',
'Content-Type': 'application/x-www-form-urlencoded'
},
body: new URLSearchParams({
grant_type: 'authorization_code',
code: '<string>',
redirect_uri: '<string>',
code_verifier: '<string>',
refresh_token: '<string>',
scope: '<string>'
})
};
fetch('https://api.sharedgraph.com/api/auth/oauth2/token', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.sharedgraph.com/api/auth/oauth2/token"
payload = {
"grant_type": "authorization_code",
"code": "<string>",
"redirect_uri": "<string>",
"code_verifier": "<string>",
"refresh_token": "<string>",
"scope": "<string>"
}
headers = {
"Authorization": "Basic <encoded-value>",
"Content-Type": "application/x-www-form-urlencoded"
}
response = requests.post(url, data=payload, headers=headers)
print(response.text){
"access_token": "<string>",
"expires_in": 123,
"expires_at": 123,
"token_type": "Bearer",
"scope": "<string>",
"refresh_token": "<string>",
"id_token": "<string>"
}{
"error": "unknown_or_immutable_field",
"message": "<string>",
"error_description": "<string>",
"error_uri": "<string>"
}{
"error": "unknown_or_immutable_field",
"message": "<string>",
"error_description": "<string>",
"error_uri": "<string>"
}{
"error": "unknown_or_immutable_field",
"message": "<string>",
"error_description": "<string>",
"error_uri": "<string>"
}{
"error": "unknown_or_immutable_field",
"message": "<string>",
"error_description": "<string>",
"error_uri": "<string>"
}{
"error": "unknown_or_immutable_field",
"message": "<string>",
"error_description": "<string>",
"error_uri": "<string>"
}{
"error": "unknown_or_immutable_field",
"message": "<string>",
"error_description": "<string>",
"error_uri": "<string>"
}{
"error": "unknown_or_immutable_field",
"message": "<string>",
"error_description": "<string>",
"error_uri": "<string>"
}{
"error": "unknown_or_immutable_field",
"message": "<string>",
"error_description": "<string>",
"error_uri": "<string>"
}{
"error": "unknown_or_immutable_field",
"message": "<string>",
"error_description": "<string>",
"error_uri": "<string>"
}{
"error": "unknown_or_immutable_field",
"message": "<string>",
"error_description": "<string>",
"error_uri": "<string>"
}{
"error": "unknown_or_immutable_field",
"message": "<string>",
"error_description": "<string>",
"error_uri": "<string>"
}OAuth
Exchange a code or rotate a refresh token
Confidential client authentication uses client_secret_basic (HTTP Basic). Account cookies and social bearer credentials do not authenticate the client. Origin may be omitted; if supplied it must match exactly. Access tokens live 300 seconds; refresh tokens 30 days. Rotation is strict: never reuse a rotated refresh token. Refresh scope cannot expand the grant.
POST
/
api
/
auth
/
oauth2
/
token
Exchange a code or rotate a refresh token
curl --request POST \
--url https://api.sharedgraph.com/api/auth/oauth2/token \
--header 'Authorization: Basic <encoded-value>' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data grant_type=authorization_code \
--data 'code=<string>' \
--data 'redirect_uri=<string>' \
--data 'code_verifier=<string>' \
--data 'refresh_token=<string>' \
--data 'scope=<string>'const options = {
method: 'POST',
headers: {
Authorization: 'Basic <encoded-value>',
'Content-Type': 'application/x-www-form-urlencoded'
},
body: new URLSearchParams({
grant_type: 'authorization_code',
code: '<string>',
redirect_uri: '<string>',
code_verifier: '<string>',
refresh_token: '<string>',
scope: '<string>'
})
};
fetch('https://api.sharedgraph.com/api/auth/oauth2/token', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.sharedgraph.com/api/auth/oauth2/token"
payload = {
"grant_type": "authorization_code",
"code": "<string>",
"redirect_uri": "<string>",
"code_verifier": "<string>",
"refresh_token": "<string>",
"scope": "<string>"
}
headers = {
"Authorization": "Basic <encoded-value>",
"Content-Type": "application/x-www-form-urlencoded"
}
response = requests.post(url, data=payload, headers=headers)
print(response.text){
"access_token": "<string>",
"expires_in": 123,
"expires_at": 123,
"token_type": "Bearer",
"scope": "<string>",
"refresh_token": "<string>",
"id_token": "<string>"
}{
"error": "unknown_or_immutable_field",
"message": "<string>",
"error_description": "<string>",
"error_uri": "<string>"
}{
"error": "unknown_or_immutable_field",
"message": "<string>",
"error_description": "<string>",
"error_uri": "<string>"
}{
"error": "unknown_or_immutable_field",
"message": "<string>",
"error_description": "<string>",
"error_uri": "<string>"
}{
"error": "unknown_or_immutable_field",
"message": "<string>",
"error_description": "<string>",
"error_uri": "<string>"
}{
"error": "unknown_or_immutable_field",
"message": "<string>",
"error_description": "<string>",
"error_uri": "<string>"
}{
"error": "unknown_or_immutable_field",
"message": "<string>",
"error_description": "<string>",
"error_uri": "<string>"
}{
"error": "unknown_or_immutable_field",
"message": "<string>",
"error_description": "<string>",
"error_uri": "<string>"
}{
"error": "unknown_or_immutable_field",
"message": "<string>",
"error_description": "<string>",
"error_uri": "<string>"
}{
"error": "unknown_or_immutable_field",
"message": "<string>",
"error_description": "<string>",
"error_uri": "<string>"
}{
"error": "unknown_or_immutable_field",
"message": "<string>",
"error_description": "<string>",
"error_uri": "<string>"
}{
"error": "unknown_or_immutable_field",
"message": "<string>",
"error_description": "<string>",
"error_uri": "<string>"
}Authorizations
client_secret_basic: registered client identifier and secret.
Body
application/x-www-form-urlencoded
- Option 1
- Option 2
Available options:
authorization_code, refresh_token Allowed value:
"authorization_code"Minimum string length:
1Minimum string length:
1Minimum string length:
1