Get or refresh the tokens of `bl`
POST
/api/v1/cli/token
const url = 'https://example.com/api/v1/cli/token';const options = { method: 'POST', headers: {DPoP: 'example', 'Content-Type': 'application/x-www-form-urlencoded'}, body: new URLSearchParams({grant_type: 'example', device_code: 'example', refresh_token: 'example'})};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://example.com/api/v1/cli/token \ --header 'Content-Type: application/x-www-form-urlencoded' \ --header 'DPoP: example' \ --data grant_type=example \ --data device_code=example \ --data refresh_token=exampleWith grant_type=urn:ietf:params:oauth:grant-type:device_code, polls for the approval (RFC 8628 §3.4: authorization_pending, slow_down, access_denied, expired_token). With grant_type=refresh_token, rotates the refresh token: the old one stops working, and presenting it again ends the whole session (RFC 9700). Every call needs a DPoP proof of the key the device code was bound to.
Authorizations
Section titled “Authorizations”- None
Parameters
Section titled “Parameters”Header Parameters
Section titled “Header Parameters”DPoP
required
string
A DPoP proof for this request.
Request Bodyrequired
Section titled “Request Bodyrequired”Media typeapplication/x-www-form-urlencoded
object
grant_type
required
urn:ietf:params:oauth:grant-type:device_code or refresh_token.
string
device_code
string | null
refresh_token
string | null
Example generated
grant_type=example&device_code=example&refresh_token=exampleResponses
Section titled “Responses”OK.
Media typeapplication/json
object
access_token
required
Opaque, bound to the DPoP key, valid for 10 minutes.
string
token_type
required
DPoP.
string
expires_in
required
integer format: int64
refresh_token
required
Opaque and bound to the DPoP key; every refresh replaces it.
string
Example generated
{ "access_token": "example", "token_type": "example", "expires_in": 1, "refresh_token": "example"}An OAuth error, e.g. authorization_pending while the user has not decided.
Media typeapplication/json
An OAuth 2.0 error (RFC 6749 §5.2).
object
error
required
string
error_description
required
string
Example
{ "error": "invalid_request"}