Tokens

Create new access and refresh tokens

POST
/api/tokens

The refresh token is returned in the body of the request or as a hardened cookie, depending on configuration. A cookie should be used when the client is running in an insecure environment such as a web browser, and cannot adequately protect the refresh token against unauthorized access.

Authorization

basic_auth
headerAuthorizationBasic <token>

Response Body

OK

application/json
  1. response
access_token?string
refresh_token?string
access_expiration?string
Formatdate-time
refresh_expiration?string
Formatdate-time
curl -X POST "https://example.com/api/tokens"
{  "access_token": "string",  "refresh_token": "string",  "access_expiration": "2019-08-24T14:15:22Z",  "refresh_expiration": "2019-08-24T14:15:22Z"}