Refresh Token (Deprecated)

Deprecated compatibility endpoint. Prefer the OAuth2 token endpoint with grant_type=refresh_token.

OAuth token requests should be sent as application/x-www-form-urlencoded, as specified by OAuth 2.0. JSON requests remain accepted for backwards compatibility.

Request new access and refresh tokens. Upon requesting new tokens, both old access_token and refresh_token values will be invalidated - make sure you update the refresh_token in your database every time you call this endpoint.
New refresh tokens should be requested at least once every 30 days (daily or weekly is fine) in order to keep the connection alive.
If you receive a 401 or 403 response, delete the old refresh token and disconnect the user.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Body Params
string
enum
required

Use the refresh token grant to obtain a new access token pair.

Allowed:
string
required
length ≥ 1

This token allows access the endpoints protected by scope.

string

Optional RFC 8707 resource indicator. Ignored for standard OAuth clients — any value (including an empty string) is accepted and never read. For public MCP dynamic client registration clients it is required and must match the MCP resource URL; that check is enforced in business logic once the client is resolved.

uuid
required
length ≥ 1

The client_id received from Spendesk.

string
length ≥ 1

The client_secret received from Spendesk. Required for confidential clients using client_secret_post; omit for public PKCE clients using token_endpoint_auth_method=none.

Headers
string
enum
Defaults to application/json

Generated from available request content types

Allowed:
Responses

Language
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json