Crosscheck
API Reference Authentication

Refresh OAuth Token

POSThttps://api-v2.crosscheck.cloud/api/v1/oauth/token

Use the refresh-token grant to obtain a new OAuth access token and refresh token.

These OAuth tokens authenticate the Crosscheck MCP server. REST endpoints in this reference require a Crosscheck session JWT; OAuth tokens cannot be substituted for a session token.

Authentication

No Authorization header is required. Supply the OAuth grant fields below. Tokens and authorization codes in these examples are placeholders.

Body Parameters

application/json

The refresh-token grant.

The OAuth client ID.

The refresh token issued by the OAuth flow.

Headers

Accept

JSON request and response format.

application/json
Content-Type

JSON request and response format.

application/json

Responses

200 OK
access_tokenstringOAuth access token for the MCP server.
token_typestringAlways Bearer.
expires_inintegerToken lifetime in seconds (3600).
refresh_tokenstringToken used to obtain a new access token.
scopestring | nullGranted OAuth scope.
400 Invalid request

The API returns success, error, code and statusCode. Validation errors also include details. Select this status in the example panel to inspect the shape.

Selected fields and abbreviated examples are shown. Additional fields and error codes depend on the resource, permissions, plan and retention state.