Skip to main content
The token endpoint accepts authorization-code and refresh-token grants. Token responses include Cache-Control: no-store and Pragma: no-cache.

Exchange an authorization code

Refresh an access token

Response

Every successful refresh rotates both tokens. Persist the new values atomically before another worker can refresh the same installation. Reusing the previous refresh token revokes the entire token family and its active access token. Authorization codes and rotated refresh tokens are not retryable credentials. Start a new authorization after invalid_grant unless you can prove another worker completed the request and stored its response.