Auth endpoints
Exchange code for tokens
Exchange a one-time authorization code for an access token and refresh token.
POST
Exchanges the authorization code from the consent flow for an access token and refresh token. The code is single-use and expires 10 minutes after it is issued.
The authorization code goes in the
Authorization header — not the access token. Your client secret goes in the request body.Headers
string
required
Bearer <AUTH_CODE> — the code returned to your redirect_uri.Body
string
required
Your MCP OAuth client secret.
Response
string
Token for authenticating API requests. Valid for 1 hour.
string
ISO 8601 timestamp when the access token expires.
string
Token for getting a new token pair. Valid for 365 days.
string
ISO 8601 timestamp when the refresh token expires.