All the major OAuth providers. One profile API.Explore the quickstart
Documentation navigation

Code exchange

Client credentials are in the JSON body, not Basic auth. One-time redemption; no automatic retries after ambiguous failure. Token expires in 900 seconds.

On this page
POSThttps://api.anyoauth.com/v1/token

Authentication: Client ID and secret in JSON; confidential backend only.

Request

Content type: application/json.

FieldTypeRequiredDescription and constraints
grant_type"authorization_code"Yes
client_idstringYesmaxLength: 100
client_secretstringYesminLength: 1; maxLength: 200
codestringYesminLength: 1; maxLength: 200
redirect_uristringYesExact registered HTTPS URL or HTTP loopback; no credentials, query or fragment. maxLength: 2048; format: uri; x-validation: redirect
code_verifierstringYespattern: ^[A-Za-z0-9._~-]{43,128}$
Illustrative JSON request
{
"grant_type": "authorization_code",
"client_id": "YOUR_CLIENT_ID",
"client_secret": "YOUR_CLIENT_SECRET",
"code": "CALLBACK_CODE",
"redirect_uri": "https://your-app.example/auth/callback",
"code_verifier": "dBjftJeZ4CVP-mB92K27uhbUJU1p1r_wW1gFWFOEjXk"
}

SDK and HTTP examples

Code exchange
import { AnyOAuth } from "@anyoauth/node";

const client = new AnyOAuth({
clientId: process.env.ANYOAUTH_CLIENT_ID ?? "YOUR_CLIENT_ID",
clientSecret: process.env.ANYOAUTH_CLIENT_SECRET ?? "YOUR_CLIENT_SECRET",
baseUrl: process.env.ANYOAUTH_API_ORIGIN ?? "https://api.anyoauth.com",
});

const token = await client.exchangeCode({
code: process.env.ANYOAUTH_CODE ?? "CALLBACK_CODE",
redirectUri: process.env.ANYOAUTH_REDIRECT_URI ?? "https://your-app.example/auth/callback",
codeVerifier: process.env.ANYOAUTH_CODE_VERIFIER ?? "dBjftJeZ4CVP-mB92K27uhbUJU1p1r_wW1gFWFOEjXk"
});

@anyoauth/node on GitHubConfidential backend SDK

Sample input bindings are illustrative. In a callback handler, take code and transaction values from the validated request and initiating session. Client-only SDKs do not perform confidential exchange.

Response

Success status: 200.

FieldTypeRequiredDescription and constraints
access_tokenstringYespattern: ^aop_[A-Za-z0-9_-]{43}$
token_type"Bearer"Yes
expires_in900Yes
scope"profile"Yes
Illustrative JSON response
{
"access_token": "aop_aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
"token_type": "Bearer",
"expires_in": 900,
"scope": "profile"
}

Errors

Application errors use the shared error model. Infrastructure may return non-JSON responses; SDKs expose structured transport/protocol errors. Do not automatically retry a one-time code exchange.

FieldTypeRequiredDescription and constraints
errorstringYes
messagestringNo
Illustrative error response
{
"error": "request_failed",
"message": "The request could not be completed."
}

Contract source

This page, its field tables and sample inputs derive from OpenAPI version 0.1.0. Download OpenAPI · Download JSON Schema · Request schema · Response schema