Skip to content

/oauth2/token

POST
/oauth2/token
curl --request POST \
--url https://gymgym.club/api/auth/oauth2/token \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "grant_type": "example", "client_id": "example", "client_secret": "example", "code": "example", "code_verifier": "example", "redirect_uri": "https://example.com", "refresh_token": "example", "resource": [ "example" ], "scope": "example" }'

Obtain an OAuth2.1 access token

DPoP
string

RFC 9449 DPoP proof JWT for issuing DPoP-bound tokens

Media typeapplication/json
object
grant_type
required

OAuth2 grant type

string
client_id

OAuth2 client ID

string
client_secret

OAuth2 client secret

string
code

Authorization code (for authorization_code grant)

string
code_verifier

PKCE code verifier (for authorization_code grant)

string
redirect_uri

Redirect URI (for authorization_code grant)

string format: uri
refresh_token

Refresh token (for refresh_token grant)

string
resource
One of:

Single resource (URL)

string
scope

Requested scopes (for client_credentials grant)

string
Examplegenerated
{
"grant_type": "example",
"client_id": "example",
"client_secret": "example",
"code": "example",
"code_verifier": "example",
"redirect_uri": "https://example.com",
"refresh_token": "example",
"resource": [
"example"
],
"scope": "example"
}

Access token response

Media typeapplication/json
object
access_token
required

The access token issued by the authorization server

string
token_type
required

The type of the token issued

string
Allowed values: Bearer DPoP
expires_in
required

Lifetime in seconds of the access token

number
refresh_token

Refresh token, if issued

string
scope

Scopes granted by the access token

string
id_token

ID Token (if OpenID Connect)

string
Example
{
"token_type": "Bearer"
}

Invalid request or error response

Media typeapplication/json
object
error
required
string
error_description
string
error_uri
string
Examplegenerated
{
"error": "example",
"error_description": "example",
"error_uri": "example"
}

Unauthorized. Due to missing or invalid authentication.

Media typeapplication/json
object
message
required
string
Examplegenerated
{
"message": "example"
}

Forbidden. You do not have permission to access this resource or to perform this action.

Media typeapplication/json
object
message
string
Examplegenerated
{
"message": "example"
}

Not Found. The requested resource was not found.

Media typeapplication/json
object
message
string
Examplegenerated
{
"message": "example"
}

Too Many Requests. You have exceeded the rate limit. Try again later.

Media typeapplication/json
object
message
string
Examplegenerated
{
"message": "example"
}

Internal Server Error. This is a problem with the server that you cannot fix.

Media typeapplication/json
object
message
string
Examplegenerated
{
"message": "example"
}