Exchange a code, refresh a token or authenticate a client

The OAuth 2.0 token endpoint.

  • authorization_code with PKCE returns an access token and a refresh token for
    the taxpayer that consented, plus grant_id, taxpayer_id, tin and
    taxpayer_name so you can map it to your own records.
  • refresh_token rotates the refresh token. Reusing an already-rotated refresh
    token revokes every token of that grant.
  • client_credentials returns an organization-level access token (no taxpayer).

Access tokens last one hour. Send them as Authorization: Bearer <token>.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Form Data
string
required
string | null
string | null
string | null
string | null
string | null
string | null
Headers
string | null
Responses

Language
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json