Deprecated

OAuth2: one token endpoint for code exchange and refresh

OAuth2 apps now use a single token endpoint, /oauth2/token/create, both to exchange an authorization code (grant_type=authorization_code) and to refresh tokens (grant_type=refresh_token). Send token requests as application/x-www-form-urlencoded, as specified by OAuth 2.0; JSON bodies remain accepted for backwards compatibility.

curl --request POST \
     --url https://public-api.spendesk.com/v1/oauth2/token/create \
     --header 'content-type: application/x-www-form-urlencoded' \
     --data grant_type=refresh_token \
     --data client_id=<your_client_id> \
     --data refresh_token=<your_refresh_token>
🚧

Deprecated

The /oauth2/token/refresh endpoint is deprecated and only remains available temporarily. Move your refresh calls to /oauth2/token/create — see How to Authenticate.