Skip to main content
POST
Exchange authorization code for OAuth token

Headers

x-signature
string

HMAC-SHA256 signature: HMAC-SHA256(secretKey, timestamp + METHOD + path + body). Required for API-key authenticated requests (JWT/OAuth session auth is exempt).

x-timestamp
string

Request timestamp in epoch milliseconds. Required with x-signature for API-key auth. Rejected if drift exceeds 5 minutes.

Body

application/json
grant_type
string
required
Example:

"authorization_code"

code
string
required
redirect_uri
string
required
Example:

"http://127.0.0.1:8765/callback"

client_id
string
required
Example:

"echozero-cli"

code_verifier
string
required

Response

201 - undefined