OAuth 2.1

Get a token

Form body (application/x-www-form-urlencoded). authorization_code: code + code_verifier → a 1-hour access token (mcp_…) + a 60-day refresh token (mcpr_…). refresh_token: every refresh returns a new pair and revokes the old one. A code works once; reusing it revokes the tokens issued from that grant.

POST/oauth/token

Authorization

No authentication required.

Body application/x-www-form-urlencoded

grant_typestringrequired
Grant type.
Valuesauthorization_coderefresh_token
codestringoptional
Authorization code.
redirect_uristringoptional
Same as in authorize.
code_verifierstringoptional
PKCE verifier.
refresh_tokenstringoptional
Refresh token.
client_idstringrequired
Client id.
client_secretstringoptional
For confidential clients.
Request
curl https://ornek.solk.app/oauth/token \
  -d grant_type=authorization_code \
  -d code=Zx8… \
  -d redirect_uri=https://uygulamaniz.com/oauth/callback \
  -d client_id=crm_Jq8w… \
  -d code_verifier=$VERIFIER
Response
{
  "access_token": "mcp_uBprY6…",
  "expires_in": 3600,
  "refresh_token": "mcpr_AXksm…",
  "scope": "crm.read crm.write",
  "token_type": "Bearer"
}