Standard token management (OAuth 2.0). Use these endpoints to obtain short-lived JWT access and refresh tokens via the Resource Owner Password Credentials grant, refresh expired tokens, and complete multi-factor authentication challenges. These tokens are intended for interactive sessions and first-party UI use. For programmatic or agentic integrations, see Personal Access Tokens.
Refresh a token
This endpoint is deprecated. Please see the "Create or Refresh a Token" endpoint instead.
query Parameters
versionAn enumeration.
Refresh a token › Request Body
refresh_tokengrant_typeAn enumeration.
expiration_secondsRefresh a token › Responses
Successful Response
access_tokenBearer token for authenticating API requests
token_typeToken type, always "bearer"
expires_inToken lifetime in seconds
refresh_tokenToken used to obtain a new access token when the current one expires
accountsSet of account IDs the authenticated user has access to
Create or Refresh a standard token (JWT)
Standard Token (JWT) — Authentication
This endpoint issues short-lived JSON Web Tokens (JWTs) using the OAuth 2.0 Resource Owner Password Credentials grant. These tokens are intended for interactive sessions and first-party UI integrations where a human user supplies their credentials at login time.
For programmatic, automated, or agentic integrations, use Personal Access Tokens
(PATs) instead — see POST /users/self/pats. PATs are long-lived, carry explicit
scopes, and do not require storing a username and password.
The response includes a short-lived access token (JWT) and a refresh token. Access and refresh tokens are sensitive data and must be stored securely.
Creating a token
When the grant_type is set to password, the endpoint will authenticate the
user using the provided username and password. If the user is authenticated
successfully, the endpoint will generate an access token and a refresh token.
The access token is used to authenticate requests to other endpoints, while the refresh token is used to obtain a new access token when the current one expires.
The refresh token is a long-lived token that can be used to obtain a new access token when the current one expires. Refresh tokens cannot be used as access tokens.
Multi-Factor Authentication
If the user account is protected by multi-factor authentication (MFA), the
endpoint will respond with a 401 Unauthorized status and include a challenge
field in the response body. This field contains a unique identifier. To complete
the token creation, the client must complete the challenge by sending a request
to the /token/challenge endpoint.
Refreshing a token
When the grant_type is set to refresh_token, the endpoint will refresh the
access token using the provided refresh token.
query Parameters
versionAn enumeration.
Create or Refresh a standard token (JWT) › Request Body
grant_typeAn enumeration.
usernamepasswordaccount_idscopes^(user|admin|interna…A comma separated list of scopes.
expiration_secondsrefresh_tokenCreate or Refresh a standard token (JWT) › Responses
Successful Response
Decision Table
| Variant | Matching Criteria |
|---|---|
| type = object · requires: access_token, token_type, expires_in +2 more | |
| type = object · requires: challenge |
access_tokenBearer token for authenticating API requests
token_typeToken type, always "bearer"
expires_inToken lifetime in seconds
refresh_tokenToken used to obtain a new access token when the current one expires
accountsSet of account IDs the authenticated user has access to
Complete a Multi-Factor Authentication challenge
This endpoint serves to complete the MFA (multi-factor authentication) challenge and return an access and refresh token pair. The complete login sequence for an MFA-enabled user is as follows:
- The client sends a POST request to
/tokenwith theusernameandpasswordin the request body. - The API returns a
challengein the response body. - The client sends a POST request to
/token/challengewith thechallengeandcodein the request body. - The API returns an
access_tokenandrefresh_tokenin the response body.
Access and Refresh tokens should be treated as sensitive data and should be stored securely.
Complete a Multi-Factor Authentication challenge › Request Body
challengescopesexpiration_secondsComplete a Multi-Factor Authentication challenge › Responses
Successful Response
access_tokenBearer token for authenticating API requests
token_typeToken type, always "bearer"
expires_inToken lifetime in seconds
refresh_tokenToken used to obtain a new access token when the current one expires
accountsSet of account IDs the authenticated user has access to