Skip to main content
POST
/
oauth
/
token
Exchange Code or Refresh Token for Tokens
curl --request POST \
  --url https://signin.altostrat.io/oauth/token \
  --header 'Content-Type: application/x-www-form-urlencoded' \
  --data grant_type=authorization_code \
  --data 'client_id=<string>' \
  --data 'code=<string>' \
  --data 'redirect_uri=<string>' \
  --data 'code_verifier=<string>'
import requests

url = "https://signin.altostrat.io/oauth/token"

payload = {
"grant_type": "authorization_code",
"client_id": "<string>",
"code": "<string>",
"redirect_uri": "<string>",
"code_verifier": "<string>"
}
headers = {"Content-Type": "application/x-www-form-urlencoded"}

response = requests.post(url, data=payload, headers=headers)

print(response.text)
const options = {
method: 'POST',
headers: {'Content-Type': 'application/x-www-form-urlencoded'},
body: new URLSearchParams({
grant_type: 'authorization_code',
client_id: '<string>',
code: '<string>',
redirect_uri: '<string>',
code_verifier: '<string>'
})
};

fetch('https://signin.altostrat.io/oauth/token', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));
<?php

$curl = curl_init();

curl_setopt_array($curl, [
CURLOPT_URL => "https://signin.altostrat.io/oauth/token",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => "grant_type=authorization_code&client_id=%3Cstring%3E&code=%3Cstring%3E&redirect_uri=%3Cstring%3E&code_verifier=%3Cstring%3E",
CURLOPT_HTTPHEADER => [
"Content-Type: application/x-www-form-urlencoded"
],
]);

$response = curl_exec($curl);
$err = curl_error($curl);

curl_close($curl);

if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}
package main

import (
"fmt"
"strings"
"net/http"
"io"
)

func main() {

url := "https://signin.altostrat.io/oauth/token"

payload := strings.NewReader("grant_type=authorization_code&client_id=%3Cstring%3E&code=%3Cstring%3E&redirect_uri=%3Cstring%3E&code_verifier=%3Cstring%3E")

req, _ := http.NewRequest("POST", url, payload)

req.Header.Add("Content-Type", "application/x-www-form-urlencoded")

res, _ := http.DefaultClient.Do(req)

defer res.Body.Close()
body, _ := io.ReadAll(res.Body)

fmt.Println(string(body))

}
HttpResponse<String> response = Unirest.post("https://signin.altostrat.io/oauth/token")
.header("Content-Type", "application/x-www-form-urlencoded")
.body("grant_type=authorization_code&client_id=%3Cstring%3E&code=%3Cstring%3E&redirect_uri=%3Cstring%3E&code_verifier=%3Cstring%3E")
.asString();
require 'uri'
require 'net/http'

url = URI("https://signin.altostrat.io/oauth/token")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/x-www-form-urlencoded'
request.body = "grant_type=authorization_code&client_id=%3Cstring%3E&code=%3Cstring%3E&redirect_uri=%3Cstring%3E&code_verifier=%3Cstring%3E"

response = http.request(request)
puts response.read_body
{
  "access_token": "<string>",
  "refresh_token": "<string>",
  "id_token": "<string>",
  "token_type": "Bearer",
  "expires_in": 86400
}
{
"error": "<string>",
"error_description": "<string>"
}

Body

application/x-www-form-urlencoded
grant_type
enum<string>
Available options:
authorization_code
client_id
string
code
string
redirect_uri
string<uri>
code_verifier
string

Response

Successfully exchanged for a new set of tokens.

access_token
string

The JWT used to call protected APIs. See AccessTokenPayload.

refresh_token
string

A long-lived token for obtaining a new access_token.

id_token
string

A JWT containing user profile information (claims).

token_type
string
Example:

"Bearer"

expires_in
integer
Example:

86400