API Reference › OAuth
Exchange Code for Tokens
POST
/oauth/tokenSwap the authorization code for an access token. Codes are single-use and expire quickly. Confidential apps send client_secret; public apps send code_verifier instead.
Authorization and token management. These follow the OAuth 2.0 spec and answer in plain OAuth JSON (no success/data envelope). Errors use the standard error and error_description fields.
Usage
curl -X POST "https://api.lifebots.cloud/api/v1/oauth/token" \
--data-urlencode "grant_type=authorization_code" \
--data-urlencode "client_id=your_client_id" \
--data-urlencode "client_secret=your_client_secret" \
--data-urlencode "code=AUTH_CODE" \
--data-urlencode "redirect_uri=https://yourapp.com/oauth/callback"Path parameters
None.
Body (application/x-www-form-urlencoded)
| Name | Type | Required | Description |
|---|---|---|---|
grant_type | string | yes | authorization_code |
client_id | string | yes | Your client_id. |
client_secret | string | no | Required for confidential apps. Never send from a browser or mobile app. |
code | string | yes | The code from the redirect. |
redirect_uri | string | yes | The same redirect_uri used in the authorize request. |
code_verifier | string | no | Required when the authorize request had a code_challenge (always for public apps). |
Example response
{
"access_token": "lb_at_…",
"token_type": "Bearer",
"scope": "read:profile bots:chat",
"refresh_token": "lb_rt_…",
"expires_in": 3600,
"refresh_token_expires_in": 2592000
}expires_in / refresh_token_expires_in are omitted when the app's tokens never expire; refresh_token is omitted when refresh is disabled for the app.