Auth endpoints
Refresh tokens
Rotate an expired access token using a refresh token.
POST
Issues a new access token and refresh token. Call this when the access token’s 1-hour lifetime has passed.
Body
string
required
Your MCP OAuth client secret.
string
required
The current, unused refresh token.
Response
string
New access token. Valid for 1 hour.
string
ISO 8601 timestamp when the new access token expires.
string
New refresh token. Valid for 365 days. Replaces the one you sent.
string
ISO 8601 timestamp when the new refresh token expires.