Skip to main content
POST
Issues a new access token and refresh token. Call this when the access token’s 1-hour lifetime has passed.
Both tokens rotate on every call. The refresh token you submit is invalidated immediately — always store the new refreshToken from the response.

Body

string
required
Your MCP OAuth client secret.
string
required
The current, unused refresh token.

Response

string
New access token. Valid for 1 hour.
string
ISO 8601 timestamp when the new access token expires.
string
New refresh token. Valid for 365 days. Replaces the one you sent.
string
ISO 8601 timestamp when the new refresh token expires.

Errors