Crosscheck
API Reference Authentication

Get Access Token

POSThttps://api-v2.crosscheck.cloud/api/v1/oauth/token

Exchange an authorization code for an OAuth access token and refresh token using PKCE (S256). Use the code returned by the Crosscheck authorization flow.

These OAuth tokens authenticate the Crosscheck MCP server. REST endpoints in this reference require a Crosscheck session JWT; OAuth tokens cannot be substituted for a session token.

Authentication

No Authorization header is required. Supply the OAuth grant fields below. Tokens and authorization codes in these examples are placeholders.

Body Parameters

application/json

The authorization-code grant.

The registered OAuth application client ID.

The code received at your redirect URI.

The original PKCE verifier used to generate the S256 challenge.

The redirect URI used during authorization.

Headers

Accept

JSON request and response format.

application/json
Content-Type

JSON request and response format.

application/json

Responses

200 OK
access_tokenstringOAuth access token for the MCP server.
token_typestringAlways Bearer.
expires_inintegerToken lifetime in seconds (3600).
refresh_tokenstringToken used to obtain a new access token.
scopestring | nullGranted OAuth scope.
400 Invalid request

The API returns success, error, code and statusCode. Validation errors also include details. Select this status in the example panel to inspect the shape.

Selected fields and abbreviated examples are shown. Additional fields and error codes depend on the resource, permissions, plan and retention state.