Get Access Token
https://api-v2.crosscheck.cloud/api/v1/oauth/tokenExchange an authorization code for an OAuth access token and refresh token using PKCE (S256). Use the code returned by the Crosscheck authorization flow.
Authentication
No Authorization header is required. Supply the OAuth grant fields below. Tokens and authorization codes in these examples are placeholders.
Body Parameters
application/jsonThe authorization-code grant.
The registered OAuth application client ID.
The code received at your redirect URI.
The original PKCE verifier used to generate the S256 challenge.
The redirect URI used during authorization.
Headers
AcceptJSON request and response format.
application/jsonContent-TypeJSON request and response format.
application/jsonResponses
200 OK
access_tokenstring | OAuth access token for the MCP server. |
|---|---|
token_typestring | Always Bearer. |
expires_ininteger | Token lifetime in seconds (3600). |
refresh_tokenstring | Token used to obtain a new access token. |
scopestring | null | Granted OAuth scope. |
400 Invalid request
The API returns success, error, code and statusCode. Validation errors also include details. Select this status in the example panel to inspect the shape.
Selected fields and abbreviated examples are shown. Additional fields and error codes depend on the resource, permissions, plan and retention state.