---
search:
  tags:
    - OAuth
    - POST
seo:
  description: >-
    Mandatory exact resource/client/redirect and S256 verifier; single-use
    one-minute… Reference for the POST /oauth/token endpoint in the agentsub
    Gateway API.
sidebar:
  label: Token endpoint (authorization_code + PKCE)
  badge: POST
title: Token endpoint (authorization_code + PKCE)
type: openapi-operation
---
Mandatory exact resource/client/redirect and S256 verifier; single-use one-minute authorization code. Returns ten-minute ES256 resource JWT, actor_type agent or owner, scope agentsub:agent or agentsub:owner. Human resource tokens recheck current backend Clerk verified-human identity before owner controls. No refresh tokens.

`POST /oauth/token`

**Request body** (`application/x-www-form-urlencoded`, required)

- `grant_type` (string, required)
- `code` (string, required)
- `client_id` (string, required)
- `redirect_uri` (string<uri>, required)
- `code_verifier` (string, required)
- `resource` (string, required)

Request body example:

```json
{
  "grant_type": "authorization_code",
  "code": "string",
  "client_id": "string",
  "redirect_uri": "http://example.com",
  "code_verifier": "string",
  "resource": "string"
}
```

**Responses**

- `200` — Access token issued
- `400` — OAuth error JSON (\`invalid\_request\`, \`invalid\_client\`, \`invalid\_grant\`, \`invalid\_scope\`, \`invalid\_target\`, \`invalid\_redirect\_uri\`, \`invalid\_client\_metadata\`, \`unsupported\_grant\_type\`)
- `415` — OAuth error JSON (\`invalid\_request\`, \`invalid\_client\`, \`invalid\_grant\`, \`invalid\_scope\`, \`invalid\_target\`, \`invalid\_redirect\_uri\`, \`invalid\_client\_metadata\`, \`unsupported\_grant\_type\`)
- `503` — OAuth error JSON (\`temporarily\_unavailable\` — credentials or storage not configured)

Response example, 200:

```json
{
  "access_token": "string",
  "token_type": "Bearer",
  "expires_in": 600,
  "scope": "agentsub:agent"
}
```
