OAuth 2.1
Get a token
Form body (application/x-www-form-urlencoded). authorization_code: code + code_verifier → a 1-hour access token (mcp_…) + a 60-day refresh token (mcpr_…). refresh_token: every refresh returns a new pair and revokes the old one. A code works once; reusing it revokes the tokens issued from that grant.
Authorization
No authentication required.
Body application/x-www-form-urlencoded
grant_typestringrequiredGrant type.
Values
authorization_coderefresh_tokencodestringoptionalAuthorization code.
redirect_uristringoptionalSame as in authorize.
code_verifierstringoptionalPKCE verifier.
refresh_tokenstringoptionalRefresh token.
client_idstringrequiredClient id.
client_secretstringoptionalFor confidential clients.
Request
curl https://ornek.solk.app/oauth/token \
-d grant_type=authorization_code \
-d code=Zx8… \
-d redirect_uri=https://uygulamaniz.com/oauth/callback \
-d client_id=crm_Jq8w… \
-d code_verifier=$VERIFIERconst res = await fetch("https://ornek.solk.app/oauth/token", {
method: "POST",
body: new URLSearchParams({
grant_type: "authorization_code",
code: "Zx8…",
redirect_uri: "https://uygulamaniz.com/oauth/callback",
client_id: "crm_Jq8w…",
code_verifier: "verifier"
}),
});
const data = await res.json();import requests
r = requests.post("https://ornek.solk.app/oauth/token", data={
"grant_type": "authorization_code",
"code": "Zx8…",
"redirect_uri": "https://uygulamaniz.com/oauth/callback",
"client_id": "crm_Jq8w…",
"code_verifier": "verifier",
})
print(r.json())Response
{
"access_token": "mcp_uBprY6…",
"expires_in": 3600,
"refresh_token": "mcpr_AXksm…",
"scope": "crm.read crm.write",
"token_type": "Bearer"
}