Skip to main content
POST
Exchanges the authorization code from the consent flow for an access token and refresh token. The code is single-use and expires 10 minutes after it is issued.
The authorization code goes in the Authorization header — not the access token. Your client secret goes in the request body.

Headers

string
required
Bearer <AUTH_CODE> — the code returned to your redirect_uri.

Body

string
required
Your MCP OAuth client secret.

Response

string
Token for authenticating API requests. Valid for 1 hour.
string
ISO 8601 timestamp when the access token expires.
string
Token for getting a new token pair. Valid for 365 days.
string
ISO 8601 timestamp when the refresh token expires.

Errors