Exchange OAuth code for tokens (PKCE)
Client
Exchange OAuth code for tokens (PKCE)
Exchange the insforge_code (received from OAuth callback) for access and refresh tokens.
This endpoint is used for PKCE flow in mobile/desktop/server clients:
- After OAuth callback, your redirect_uri receives
insforge_codeparameter - Call this endpoint with the code and your original code_verifier
- Receive access token and refresh token in response
The code_verifier must match the code_challenge sent during OAuth initiation.
POST
Exchange OAuth code for tokens (PKCE)
Query Parameters
Client type determines how refresh tokens are returned:
- web: Refresh token stored in httpOnly cookie, csrfToken returned in response
- mobile/desktop/server: refreshToken returned directly in response body
Available options:
web, mobile, desktop, server Body
application/json