Skip to main content
POST
Authenticate with HTTP Basic Auth: Authorization: Basic base64(client_id:client_secret)

Body

string
required
Must be "refresh_token".
string
required
From a previous verify-code or token response.

Response

Same shape as POST /oauth/verify-code. Includes a new access_token, new refresh_token, and updated id_token.
Each refresh token can only be used once. Always save the new refresh_token from the response. If you lose it, the agent will need to sign in again.

Errors

Last modified on March 19, 2026