Skip to main content
POST
/
oauth
/
token
Issue OAuth access token
curl --request POST \
  --url https://api.coinlist.co/oauth/token \
  --header 'Content-Type: application/x-www-form-urlencoded' \
  --data 'client_id=<string>' \
  --data 'client_secret=<string>' \
  --data 'code=<string>' \
  --data 'code_verifier=<string>' \
  --data 'redirect_uri=<string>' \
  --data 'refresh_token=<string>'
import requests

url = "https://api.coinlist.co/oauth/token"

payload = {
    "client_id": "<string>",
    "client_secret": "<string>",
    "code": "<string>",
    "code_verifier": "<string>",
    "redirect_uri": "<string>",
    "refresh_token": "<string>"
}
headers = {"Content-Type": "application/x-www-form-urlencoded"}

response = requests.post(url, data=payload, headers=headers)

print(response.text)
const options = {
  method: 'POST',
  headers: {'Content-Type': 'application/x-www-form-urlencoded'},
  body: new URLSearchParams({
    client_id: '<string>',
    client_secret: '<string>',
    code: '<string>',
    code_verifier: '<string>',
    redirect_uri: '<string>',
    refresh_token: '<string>'
  })
};

fetch('https://api.coinlist.co/oauth/token', options)
  .then(res => res.json())
  .then(res => console.log(res))
  .catch(err => console.error(err));
<?php

$curl = curl_init();

curl_setopt_array($curl, [
  CURLOPT_URL => "https://api.coinlist.co/oauth/token",
  CURLOPT_RETURNTRANSFER => true,
  CURLOPT_ENCODING => "",
  CURLOPT_MAXREDIRS => 10,
  CURLOPT_TIMEOUT => 30,
  CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
  CURLOPT_CUSTOMREQUEST => "POST",
  CURLOPT_POSTFIELDS => "client_id=%3Cstring%3E&client_secret=%3Cstring%3E&code=%3Cstring%3E&code_verifier=%3Cstring%3E&redirect_uri=%3Cstring%3E&refresh_token=%3Cstring%3E",
  CURLOPT_HTTPHEADER => [
    "Content-Type: application/x-www-form-urlencoded"
  ],
]);

$response = curl_exec($curl);
$err = curl_error($curl);

curl_close($curl);

if ($err) {
  echo "cURL Error #:" . $err;
} else {
  echo $response;
}
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.coinlist.co/oauth/token"

	payload := strings.NewReader("client_id=%3Cstring%3E&client_secret=%3Cstring%3E&code=%3Cstring%3E&code_verifier=%3Cstring%3E&redirect_uri=%3Cstring%3E&refresh_token=%3Cstring%3E")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Content-Type", "application/x-www-form-urlencoded")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(string(body))

}
HttpResponse<String> response = Unirest.post("https://api.coinlist.co/oauth/token")
  .header("Content-Type", "application/x-www-form-urlencoded")
  .body("client_id=%3Cstring%3E&client_secret=%3Cstring%3E&code=%3Cstring%3E&code_verifier=%3Cstring%3E&redirect_uri=%3Cstring%3E&refresh_token=%3Cstring%3E")
  .asString();
require 'uri'
require 'net/http'

url = URI("https://api.coinlist.co/oauth/token")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/x-www-form-urlencoded'
request.body = "client_id=%3Cstring%3E&client_secret=%3Cstring%3E&code=%3Cstring%3E&code_verifier=%3Cstring%3E&redirect_uri=%3Cstring%3E&refresh_token=%3Cstring%3E"

response = http.request(request)
puts response.read_body
{
  "access_token": "<string>",
  "expires_in": 123,
  "token_type": "<string>",
  "id_token": "<string>",
  "refresh_token": "<string>"
}
{
  "error": "<string>",
  "error_description": "<string>"
}
{
  "error": "<string>",
  "error_description": "<string>"
}
{
  "error": "<string>",
  "error_description": "<string>"
}

Body

application/x-www-form-urlencoded

Token request params

grant_type
enum<string>
required

OAuth grant type. Supported values are authorization_code, client_credentials, and refresh_token.

Available options:
authorization_code,
client_credentials,
refresh_token
client_id
string

OAuth client identifier. Required for all grant types when client authentication is sent in the request body.

client_secret
string

OAuth client secret. Required for all grant types when client authentication is sent in the request body.

code
string

Authorization code received from the /oauth/authorize endpoint. Required when grant_type is authorization_code.

code_verifier
string

PKCE code verifier corresponding to the code_challenge sent to /oauth/authorize. Required when grant_type is authorization_code.

redirect_uri
string<uri>

Must match the redirect_uri used in the original /oauth/authorize request. Required when grant_type is authorization_code.

refresh_token
string

Required when grant_type is refresh_token.

Response

Successful token response

access_token
string
required

The access token

expires_in
integer
required

Token lifetime in seconds

token_type
string
required

Token type, e.g. Bearer

id_token
string

OpenID Connect ID token

refresh_token
string

The refresh token