Skip to main content
POST
Exchange device code or refresh token

Body

Exchange a device code or refresh token. Supply the matching grant_type and credential using JSON or form encoding.

device_code
string
required

device_code returned by POST /v1/auth/device/code. Required for a device-code grant.

Minimum string length: 1
grant_type
string
required

Selects the device authorization grant to poll or exchange a device code.

Allowed value: "urn:ietf:params:oauth:grant-type:device_code"

Response

Token pair (snake_case OAuth wire format). Body (form-encoded or JSON): grant_type=urn:ietf:params:oauth:grant-type:device_code with device_code, or grant_type=refresh_token with refresh_token. Refresh tokens rotate on every grant — always store the new one.

access_token
string
required

Bearer access token for authenticated Photon API requests.

expires_in
number
required

Access-token validity in seconds, derived from its expiry and issue times; defaults to 300 when unavailable.

refresh_token
string
required

Refresh token for the next refresh grant. Tokens rotate on every grant; replace the stored value with this one.

user
object
required

Profile of the authenticated user.

authentication_method
string

Authentication method used for the device login, when returned. Omitted for refresh grants.

{key}
any