Create a one-time code that lets a desktop app or a script running on the same machine obtain its own tokens for the current user. The code is bound to the given PKCE challenge and expires after 60 seconds. Bots and sessions waiting for a 2FA setup cannot mint codes.
POST
/auth/app-login/code
curl \
--request POST 'http://api.example.com/auth/app-login/code' \
--header "Authorization: $API_KEY" \
--header "Content-Type: application/json" \
--data '{
"code_challenge": "E9Melhoa2OwvFrEMTJguCHaoeK1t8URWbuGJSstw-cM"
}'
Request examples
{
"code_challenge": "E9Melhoa2OwvFrEMTJguCHaoeK1t8URWbuGJSstw-cM"
}
Response examples (201)
{
"code": "string"
}