---
id: post-oidc-token-sandbox
title: "Token Endpoint"
description: "OpenID Connect token endpoint that exchanges an authorization code for access and ID tokens. Client authentication is required using HTTP Basic Auth with `client_id` as username and `client_secret` as password."
sidebar_label: "Token Endpoint"
hide_title: true
hide_table_of_contents: true
api: eJzlWM1SIzcQfpUunaBqbLMsuUylUgGzSZykAgVs7YG4QJbaHi0aaVbS2BDX3PIkebQ8SaqlGWMbw7J7zJ4wM+r/7q8/zZJJ9MKpKihrWM7OKjSjUxhaY1AECPYODaCRlVUmQCh4ALwXBTcz9MAN8DoU1qm/OMmDsBJhah1wIdDTAQmj06TF92GoFZoQZdAEJZKQ8uDwU60cSqi9MjP45erqHE64VwKO61DAQoUCbkWUvlHyFriH2qMzvMRoo3vnUTgM8X3FvV9YJ/t/GpaxijteYkDnWX693Ir5qkDy0k4hFAjWzbhRPvrGMqboRMVDwTJG9ljO1k+MJMtY5z7Lg6sxY14UWHKWL1l4qEjCB6fMjDVNtm37vVGfagQlKSFTha5zw3MjJ/Z+w53+bn/ao2du9oXejNNh9OHEygc6sS0rrAloAr3iVaXbkg3ue4vFoje1ruzVTqOhuks69MSWnXxEEagCzlbogkJPb2eOm3CTzmz7lTE0dcnya7bRXDdkhI0zJnHKax1Yvut9tqO2pJ7SGo3CBKnFao+SNRS/VA5FuKmd2uXKU23vL0YQLCwKJYpYKYe+ssYjLJTWMEHwaEIGZe0DlDysTiVDUZ6sgzLxxfHGBF2kepBrMZ5XubSpYkhD6FCgmqOEqbPlS3aa9Ya5Xi/MVnJah8ZNk2RS0LGahwcH9GfTseMEAXsJA/ZbKOnk2LO99dGT+OtbKUHNTVT/unT9+uGq9SbimeCmqxoVtoWuytmAIqAkl23tBHoqSpR7tnGf7z2qQLKpvK9Rwt4Jcodun5TifaUc+hu1HoAyAWfodmqVtWux04BHYY30EXYfm7KNojMJc65VbHglvzhVMUnWBK6Mb5EqPIAyNP/JDT6xdYh2CZZZk3qkQC4j4i7ZkIsCe0NrgrN6Z3Ufh/+el5WmR8b2fLAOye1N10ZGUrugT85tTKEvbK0lGEujDoIMyz6LDh0dvCGLr2689cFA56wbJoiJv0/XPBpnn2nSR+ldBV6FfHRw0OxQ/2KWTjhBSVUHWC25rgDbq6bDS6Q18VidlJqjbzg1F+2Ix66Z2to8TdB3CeO+0QSNTCC6pcGjm6ODaGYrR03GPIraqfAQSVYkcLR1WH49Jq5BQXWkKWeV9eFsdDq8IjS6TBSGZSzwGXG0joieOztXEh3sXe4gRPuUvRJDYTuNkeuRSTaYvx2Qt0rgAO8DGk+FskqKwXKTwTWD5TqFagYJICkcCnYXZTzF0ra5YBmrnWY5K0KofD4YSCxtj1eqr+Iy7SvLnvK+c2dlLSJ4PqPmcxouA58Rk3lG3KfX246MH4t0Sb2aWuy4Ur/hw1qv8PSgpZupyo+Ec4NKPNkbx+cjuMOHLZrfB9onc67r1T683dBzC8lMIk4ThMrhVN2jbOl/8hFuYc/YgGmhOq50zEHFBe5ngP1Zf0ttDq3g9w+2dpSO3h0+/HDbp62SdnDq0SWbxP9+iluN5ezXD1dPY1tfq3TF6NxLmlqfaS1v0q1VBiNAUA6TMbYafqpbZGO0Vzuk4SIiDZZcUW19XVXWhR8f67kqifr58dFmI6z30FY0KyHY+/fvf/aJJ3C4XKBUvgDJA1/d9eIta45OTbtbWztaxJPigPZhFGj7e/Copz1v5+hQzcyKMGStPJ9oBOEwPubaZ8BBqpkKXMOCa40hGvNWKwmVlRBQFMZqO1PoM0DDJ7HmHAwuQOMcNTUUIWKETT5RmvgJKeF1sERRzAyELSutuBGYChbDczirdYzHU804TGutqXOlCtHPkhuDju5dWgkk3povV1NQEbeAw/7Bk5wvFos+j6/71s0Grawf/D4avvvj8l2PZIhMqqA3igc0O9KKukQTuukiCEr1Ojw4POq/7b8hWQK7kps1fyKQwrv2rr7dumur6/96yW8nKeB9GFSaK0N5ioVZtkvhms3ftriuRNzG3WJgGaPVwDKWP7ne51sX7LQexhkraOHk12y5nHCP751uGnr8qUZHK3CcsTl3seHTClGefkuWT7n2+EKB9i7aXO3Dix8ndkbcQbgh/I6Ay3LGMnZHCL/98SLula/x64s/XHyFrxt5b8arK0XMZjoyTL71rtKNtVPx+Y8VFHhSQZhehWeEI7Fr1lnG+dkl7YVJ+8WkjMSMrWnO1v8h6tM0/wEPNdWj
sidebar_class_name: "post api-method"
info_path: docs/extensions-api/igrant-io-api-documentation
custom_edit_url: null
---

> **Build this with an AI coding agent.** Install the iGrant.io Agent Skills, then ask your agent to build the integration:
>
> ```bash
> npx skills add L3-iGrant/skills
> ```


import ApiTabs from "@theme/ApiTabs";
import DiscriminatorTabs from "@theme/DiscriminatorTabs";
import MethodEndpoint from "@theme/ApiExplorer/MethodEndpoint";
import SecuritySchemes from "@theme/ApiExplorer/SecuritySchemes";
import MimeTabs from "@theme/MimeTabs";
import ParamsItem from "@theme/ParamsItem";
import ResponseSamples from "@theme/ResponseSamples";
import SchemaItem from "@theme/SchemaItem";
import SchemaTabs from "@theme/SchemaTabs";
import Markdown from "@theme/Markdown";
import OperationTabs from "@theme/OperationTabs";
import TabItem from "@theme/TabItem";

<h1 className={"openapi__heading"}>Token Endpoint</h1>

<MethodEndpoint method={"post"} path={"/v3/service/extension/oidc/{organisationId}/{sandboxOrgId}/token"}></MethodEndpoint>



OpenID Connect token endpoint that exchanges an authorization code for access and ID tokens. Client authentication is required using HTTP Basic Auth with `client_id` as username and `client_secret` as password.


## Request

<details style={{"marginBottom":"1rem"}} className={"openapi-markdown__details"} data-collapsed={false} open={true}><summary style={{}}><h3 className={"openapi-markdown__details-summary-header-params"}>Path Parameters</h3></summary><div><ul><ParamsItem className={"paramsItem"} param={{"description":"The ID of the organisation","in":"path","name":"organisationId","required":true,"schema":{"type":"string"}}}></ParamsItem><ParamsItem className={"paramsItem"} param={{"description":"Unique identifier of the sandbox organisation.","in":"path","name":"sandboxOrgId","required":true,"schema":{"type":"string"}}}></ParamsItem></ul></div></details><MimeTabs className={"openapi-tabs__mime"}><TabItem label={"application/x-www-form-urlencoded"} value={"application/x-www-form-urlencoded-schema"}><details style={{}} className={"openapi-markdown__details mime"} data-collapsed={false} open={true}><summary style={{}} className={"openapi-markdown__details-summary-mime"}><h3 className={"openapi-markdown__details-summary-header-body"}>Body</h3><strong className={"openapi-schema__required"}>required</strong></summary><div style={{"textAlign":"left","marginLeft":"1rem"}}></div><ul style={{"marginLeft":"1rem"}}><SchemaItem collapsible={false} name={"grant_type"} required={true} schemaName={"string"} qualifierMessage={"**Possible values:** [`authorization_code`]"} schema={{"type":"string","enum":["authorization_code"],"default":"authorization_code","description":"The type of grant being used"}}></SchemaItem><SchemaItem collapsible={false} name={"redirect_uri"} required={true} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"The URI to which the response will be sent, must match the redirect URI used in the Authorization Request"}}></SchemaItem><SchemaItem collapsible={false} name={"code"} required={true} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"The Authorization Code received from the Authorization Request"}}></SchemaItem></ul></details></TabItem></MimeTabs><div><div><ApiTabs label={undefined} id={undefined}><TabItem label={"200"} value={"200"}><div>

Access (and ID) token response

</div><details style={{"textAlign":"left","marginBottom":"1rem"}} className={"openapi-markdown__details"} data-collaposed={true} open={false}><summary style={{}}><strong>Response Headers</strong></summary><ul style={{"marginLeft":"1rem"}}><li className={"schemaItem"}><summary style={{}}><strong>Cache-Control</strong><span style={{"opacity":"0.6"}}> string</span></summary><div><div style={{"marginTop":".5rem","marginBottom":".5rem"}}>

Indicates that the response should not be cached.

</div></div></li></ul></details><div><MimeTabs className={"openapi-tabs__mime"} schemaType={"response"}><TabItem label={"application/json"} value={"application/json"}><SchemaTabs className={"openapi-tabs__schema"}><TabItem label={"Schema"} value={"Schema"}><details style={{}} className={"openapi-markdown__details response"} data-collapsed={false} open={true}><summary style={{}} className={"openapi-markdown__details-summary-response"}><strong>Schema</strong></summary><div style={{"textAlign":"left","marginLeft":"1rem"}}></div><ul style={{"marginLeft":"1rem"}}><SchemaItem collapsible={false} name={"access_token"} required={false} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"The JWT token that can be sent to access protected resources"}}></SchemaItem><SchemaItem collapsible={false} name={"token_type"} required={false} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"The type of the token issued (Bearer)"}}></SchemaItem><SchemaItem collapsible={false} name={"expires_in"} required={false} schemaName={"integer"} qualifierMessage={undefined} schema={{"type":"integer","description":"The duration in seconds for which the access token is valid"}}></SchemaItem><SchemaItem collapsible={false} name={"id_token"} required={false} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"The JWT that contains identity information about the user"}}></SchemaItem></ul></details></TabItem><TabItem label={"Example (from schema)"} value={"Example (from schema)"}><ResponseSamples responseExample={"{\n  \"access_token\": \"string\",\n  \"token_type\": \"string\",\n  \"expires_in\": 0,\n  \"id_token\": \"string\"\n}"} language={"json"}></ResponseSamples></TabItem></SchemaTabs></TabItem></MimeTabs></div></TabItem><TabItem label={"401"} value={"401"}><div>

Unauthorized

</div><details style={{"textAlign":"left","marginBottom":"1rem"}} className={"openapi-markdown__details"} data-collaposed={true} open={false}><summary style={{}}><strong>Response Headers</strong></summary><ul style={{"marginLeft":"1rem"}}></ul></details><div><MimeTabs className={"openapi-tabs__mime"} schemaType={"response"}><TabItem label={"application/json"} value={"application/json"}><SchemaTabs className={"openapi-tabs__schema"}><TabItem label={"Schema"} value={"Schema"}><details style={{}} className={"openapi-markdown__details response"} data-collapsed={false} open={true}><summary style={{}} className={"openapi-markdown__details-summary-response"}><strong>Schema</strong></summary><div style={{"textAlign":"left","marginLeft":"1rem"}}></div><ul style={{"marginLeft":"1rem"}}><SchemaItem collapsible={false} name={"errorCode"} required={true} schemaName={"integer"} qualifierMessage={undefined} schema={{"type":"integer","example":400}}></SchemaItem><SchemaItem collapsible={false} name={"errorDescription"} required={true} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","example":"Bad input parameter"}}></SchemaItem></ul></details></TabItem><TabItem label={"Example (from schema)"} value={"Example (from schema)"}><ResponseSamples responseExample={"{\n  \"errorCode\": 400,\n  \"errorDescription\": \"Bad input parameter\"\n}"} language={"json"}></ResponseSamples></TabItem></SchemaTabs></TabItem></MimeTabs></div></TabItem><TabItem label={"404"} value={"404"}><div>

Resource not found

</div><details style={{"textAlign":"left","marginBottom":"1rem"}} className={"openapi-markdown__details"} data-collaposed={true} open={false}><summary style={{}}><strong>Response Headers</strong></summary><ul style={{"marginLeft":"1rem"}}></ul></details><div><MimeTabs className={"openapi-tabs__mime"} schemaType={"response"}><TabItem label={"application/json"} value={"application/json"}><SchemaTabs className={"openapi-tabs__schema"}><TabItem label={"Schema"} value={"Schema"}><details style={{}} className={"openapi-markdown__details response"} data-collapsed={false} open={true}><summary style={{}} className={"openapi-markdown__details-summary-response"}><strong>Schema</strong></summary><div style={{"textAlign":"left","marginLeft":"1rem"}}></div><ul style={{"marginLeft":"1rem"}}><SchemaItem collapsible={false} name={"errorCode"} required={true} schemaName={"integer"} qualifierMessage={undefined} schema={{"type":"integer","example":400}}></SchemaItem><SchemaItem collapsible={false} name={"errorDescription"} required={true} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","example":"Bad input parameter"}}></SchemaItem></ul></details></TabItem><TabItem label={"Example (from schema)"} value={"Example (from schema)"}><ResponseSamples responseExample={"{\n  \"errorCode\": 400,\n  \"errorDescription\": \"Bad input parameter\"\n}"} language={"json"}></ResponseSamples></TabItem></SchemaTabs></TabItem></MimeTabs></div></TabItem><TabItem label={"500"} value={"500"}><div>

Internal server error

</div><details style={{"textAlign":"left","marginBottom":"1rem"}} className={"openapi-markdown__details"} data-collaposed={true} open={false}><summary style={{}}><strong>Response Headers</strong></summary><ul style={{"marginLeft":"1rem"}}></ul></details><div><MimeTabs className={"openapi-tabs__mime"} schemaType={"response"}><TabItem label={"application/json"} value={"application/json"}><SchemaTabs className={"openapi-tabs__schema"}><TabItem label={"Schema"} value={"Schema"}><details style={{}} className={"openapi-markdown__details response"} data-collapsed={false} open={true}><summary style={{}} className={"openapi-markdown__details-summary-response"}><strong>Schema</strong></summary><div style={{"textAlign":"left","marginLeft":"1rem"}}></div><ul style={{"marginLeft":"1rem"}}><SchemaItem collapsible={false} name={"errorCode"} required={true} schemaName={"integer"} qualifierMessage={undefined} schema={{"type":"integer","example":400}}></SchemaItem><SchemaItem collapsible={false} name={"errorDescription"} required={true} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","example":"Bad input parameter"}}></SchemaItem></ul></details></TabItem><TabItem label={"Example (from schema)"} value={"Example (from schema)"}><ResponseSamples responseExample={"{\n  \"errorCode\": 400,\n  \"errorDescription\": \"Bad input parameter\"\n}"} language={"json"}></ResponseSamples></TabItem></SchemaTabs></TabItem></MimeTabs></div></TabItem></ApiTabs></div></div>
      