Token Endpoint
POST/v3/service/extension/oidc/:organisationId/:sandboxOrgId/token
OpenID Connect token endpoint that exchanges an authorisation code for access and ID tokens. Client authentication is required using HTTP Basic Auth with client_id as username and client_secret as password. The sub value is resolved during this request, with the identity matching attributes or the callback of the client. The ID token holds the claims iss, sub, aud, presentation, iat and exp, and nonce when the authorisation request had one. The access token and the ID token expire after 5 minutes.
Request
Path Parameters
The ID of the organisation
Unique identifier of the sandbox organisation.
- application/x-www-form-urlencoded
Body
required
Possible values: [authorization_code]
Default value: authorization_code
The type of grant being used
The URI to which the response will be sent, must match the redirect URI used in the Authorization Request
The Authorization Code received from the Authorization Request
Responses
- 200
- 400
- 401
- 404
- 500
Access (and ID) token response
Response Headers
Cache-Control string
Indicates that the response should not be cached.
- application/json
- Schema
- Example (from schema)
Schema
The JWT token that can be sent to access protected resources
The type of the token issued (Bearer)
The number of seconds until the login session expires
The JWT that contains identity information about the user
{
"access_token": "string",
"token_type": "string",
"expires_in": 0,
"id_token": "string"
}
Bad request. The provider answers with error and error_description. The error codes are invalid_request, unsupported_grant_type, invalid_client and invalid_grant. The answer has errorCode and errorDescription when the organisation is not found.
Response Headers
- application/json
- Schema
- Example (from schema)
Schema
- Provider error
- API error
The error code, for example invalid_request, not_found or server_error
The reason for the error
{
"error": "invalid_grant",
"error_description": "Invalid session"
}
Unauthorized. The Authorization header does not use the Basic scheme.
Response Headers
WWW-Authenticate string
The authentication scheme that the endpoint accepts.
- application/json
- Schema
- Example (from schema)
- Example
Schema
The error code, for example invalid_request, not_found or server_error
The reason for the error
{
"error": "string",
"error_description": "string"
}
{
"error": "invalid_client",
"error_description": "Invalid 'Authorization' header format"
}
Not found. The Passwordless Login extension has never been enabled for the sandbox organisation.
Response Headers
- application/json
- Schema
- Example (from schema)
- Example
Schema
The error code, for example invalid_request, not_found or server_error
The reason for the error
{
"error": "string",
"error_description": "string"
}
{
"error": "not_found",
"error_description": "Not found"
}
The sub value cannot be resolved. With callbackURI the error codes are callback_failed, callback_error, invalid_response and missing_sub. With identityMatchingAttributes the error code is invalid_request. Other failures give server_error. The answer has errorCode and errorDescription when it cannot reach the provider.
Response Headers
- application/json
- Schema
- Example (from schema)
Schema
- Provider error
- API error
The error code, for example invalid_request, not_found or server_error
The reason for the error
{
"error": "callback_error",
"error_description": "The external service returned 503"
}