Exchange device code or refresh token
Exchanges an authorized device code or a refresh token for an access token and rotating refresh token. Accepts JSON and form-encoded bodies. While polling, wait at least interval seconds and increase the interval on slow_down. Store the new refresh token after every successful grant.
Body
Exchange a device code or refresh token. Supply the matching grant_type and credential using JSON or form encoding.
- Option 1
- Option 2
Response
Token pair (snake_case OAuth wire format). Body (form-encoded or JSON): grant_type=urn:ietf:params:oauth:grant-type:device_code with device_code, or grant_type=refresh_token with refresh_token. Refresh tokens rotate on every grant — always store the new one.
Bearer access token for authenticated Photon API requests.
Access-token validity in seconds, derived from its expiry and issue times; defaults to 300 when unavailable.
Refresh token for the next refresh grant. Tokens rotate on every grant; replace the stored value with this one.
Profile of the authenticated user.
Authentication method used for the device login, when returned. Omitted for refresh grants.