Skip to main content
POST
Authenticate with HTTP Basic Auth: Authorization: Basic base64(client_id:client_secret)

Body

string
required
From the POST /oauth/send-code response.
string
required
The 6-digit code the agent read from their inbox.

Response

string
The agent’s permanent, unique ID. Store this in your database — it never changes. Same concept as Google’s sub field.
string
Use to call GET /oauth/agentinfo. Expires in 1 hour.
string
Use to get a new access token via POST /oauth/token. Expires in 30 days. Single-use — each refresh gives a new one.
string
Signed JWT with agent claims. Can be decoded locally without calling Commune.
number
Access token lifetime in seconds (3600 = 1 hour).
string
Always "identity".

Errors

Last modified on March 19, 2026