const response = await fetch('https://api.commune.email/oauth/token', {
method: 'POST',
headers: {
'Authorization': `Basic ${credentials}`,
'Content-Type': 'application/json',
},
body: JSON.stringify({
grant_type: 'refresh_token',
refresh_token: storedRefreshToken,
}),
});
const data = await response.json();
// IMPORTANT: Save the new refresh_token — the old one is now invalid
resp = httpx.post(
'https://api.commune.email/oauth/token',
headers={
'Authorization': f'Basic {credentials}',
'Content-Type': 'application/json',
},
json={
'grant_type': 'refresh_token',
'refresh_token': stored_refresh_token,
},
)
data = resp.json()
# Save data['refresh_token'] — old one is invalid
curl -X POST https://api.commune.email/oauth/token \
-H "Authorization: Basic $(echo -n 'comm_client_xxx:comm_secret_xxx' | base64)" \
-H "Content-Type: application/json" \
-d '{"grant_type": "refresh_token", "refresh_token": "comm_refresh_xxx..."}'
{
"access_token": "comm_oauth_new...",
"token_type": "Bearer",
"expires_in": 3600,
"refresh_token": "comm_refresh_new...",
"id_token": "eyJhbGciOi...",
"agent_id": "agt_4f3a9b2c1d7e8a9b",
"scope": "identity"
}
Commune OAuth
Refresh Token
Exchange a refresh token for a new access token. The old refresh token is invalidated and a new one is returned.
POST
/
oauth
/
token
const response = await fetch('https://api.commune.email/oauth/token', {
method: 'POST',
headers: {
'Authorization': `Basic ${credentials}`,
'Content-Type': 'application/json',
},
body: JSON.stringify({
grant_type: 'refresh_token',
refresh_token: storedRefreshToken,
}),
});
const data = await response.json();
// IMPORTANT: Save the new refresh_token — the old one is now invalid
resp = httpx.post(
'https://api.commune.email/oauth/token',
headers={
'Authorization': f'Basic {credentials}',
'Content-Type': 'application/json',
},
json={
'grant_type': 'refresh_token',
'refresh_token': stored_refresh_token,
},
)
data = resp.json()
# Save data['refresh_token'] — old one is invalid
curl -X POST https://api.commune.email/oauth/token \
-H "Authorization: Basic $(echo -n 'comm_client_xxx:comm_secret_xxx' | base64)" \
-H "Content-Type: application/json" \
-d '{"grant_type": "refresh_token", "refresh_token": "comm_refresh_xxx..."}'
{
"access_token": "comm_oauth_new...",
"token_type": "Bearer",
"expires_in": 3600,
"refresh_token": "comm_refresh_new...",
"id_token": "eyJhbGciOi...",
"agent_id": "agt_4f3a9b2c1d7e8a9b",
"scope": "identity"
}
Authenticate with HTTP Basic Auth:
Authorization: Basic base64(client_id:client_secret)const response = await fetch('https://api.commune.email/oauth/token', {
method: 'POST',
headers: {
'Authorization': `Basic ${credentials}`,
'Content-Type': 'application/json',
},
body: JSON.stringify({
grant_type: 'refresh_token',
refresh_token: storedRefreshToken,
}),
});
const data = await response.json();
// IMPORTANT: Save the new refresh_token — the old one is now invalid
resp = httpx.post(
'https://api.commune.email/oauth/token',
headers={
'Authorization': f'Basic {credentials}',
'Content-Type': 'application/json',
},
json={
'grant_type': 'refresh_token',
'refresh_token': stored_refresh_token,
},
)
data = resp.json()
# Save data['refresh_token'] — old one is invalid
curl -X POST https://api.commune.email/oauth/token \
-H "Authorization: Basic $(echo -n 'comm_client_xxx:comm_secret_xxx' | base64)" \
-H "Content-Type: application/json" \
-d '{"grant_type": "refresh_token", "refresh_token": "comm_refresh_xxx..."}'
{
"access_token": "comm_oauth_new...",
"token_type": "Bearer",
"expires_in": 3600,
"refresh_token": "comm_refresh_new...",
"id_token": "eyJhbGciOi...",
"agent_id": "agt_4f3a9b2c1d7e8a9b",
"scope": "identity"
}
Body
string
required
Must be
"refresh_token".string
required
From a previous
verify-code or token response.Response
Same shape asPOST /oauth/verify-code. Includes a new access_token, new refresh_token, and updated id_token.
Each refresh token can only be used once. Always save the new
refresh_token from the response. If you lose it, the agent will need to sign in again.Errors
| Code | HTTP | Description |
|---|---|---|
invalid_grant | 401 | Refresh token is invalid, expired, or already used. |
unsupported_grant_type | 400 | grant_type is not "refresh_token". |
agent_inactive | 403 | Agent account has been suspended. |
Last modified on March 19, 2026
Was this page helpful?

