OAuth2 Token Endpoint (OAuth app PKCE)

Standard OAuth2 token endpoint for OAuth app credentials. Use grant_type=authorization_code to exchange an authorization code for access and refresh tokens after Request Authorization. Use grant_type=refresh_token on this same endpoint to rotate tokens and keep the connection alive.

OAuth token requests should be sent as application/x-www-form-urlencoded, as specified by OAuth 2.0. JSON requests remain accepted for backwards compatibility.

Do not use this endpoint with Public API credentials issued for server-to-server access. Those credentials must call Create Access Token on /v1/auth/token.

The legacy Refresh token endpoint remains available temporarily for backwards compatibility.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Body Params
string
enum
required

Use the authorization code grant to exchange an auth code for tokens in the OAuth app PKCE flow.

Allowed:
uuid
required
length ≥ 1

The OAuth app client_id received from Spendesk.

string
length ≥ 1

The OAuth app client_secret received from Spendesk. Required for confidential clients using client_secret_post; omit for public PKCE clients using token_endpoint_auth_method=none.

string
required
length ≥ 1

This URI must match the URI used in the Request Authorization endpoint.

string

Optional interoperability field accepted from OAuth clients. It is ignored during token exchange; the issued token retains the scope approved during authorization.

string

Optional RFC 8707 resource indicator. Ignored for standard OAuth clients — any value (including an empty string) is accepted and never read. For public MCP dynamic client registration clients it is required and must match the MCP resource URL; that check is enforced in business logic once the client is resolved.

string
required
length ≥ 1

The authorization code set on the redirect URI on the way back from connecting to Spendesk.

string
required
length between 43 and 128

This is the secret that was used to generate code_challenge you sent when starting the OAuth2 PCKE flow.

Headers
string
enum
Defaults to application/json

Generated from available request content types

Allowed:
Responses

Language
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json