Skip to main content
POST
Exchange credentials for tokens

Authorizations

x-app-id
string
header
required

App identifier (App.id, sent as the x-app-id header)

Body

application/json
grant_type
enum<string>
required

Grant type for token exchange

Available options:
password,
refresh_token,
magic_link
Example:

"password"

email
string
password
string
Example:

"SecurePassword123!"

refresh_token
string
Example:

"ref_0123456789abcdef"

token
string

Magic link token

Example:

"ml_0123456789abcdef"

scope
string

Requested scopes (space separated)

Example:

"openid profile email"

Response

200 - application/json
token
string
required

JWT authentication token

Example:

"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."

user
object
required

Authenticated user information

refresh_token
string
required

Refresh token for obtaining new access tokens

Example:

"ref_0123456789abcdef"

expires_at
string
required

Token expiration timestamp (ISO)

Example:

"2025-01-01T01:00:00.000Z"