Exchange a one-time code minted through the browser for a new access and refresh token pair. The code can be used once, and only with the PKCE code verifier matching its challenge. The response has the same shape as a successful login and never sets cookies.
POST
/auth/app-login/token
curl \
--request POST 'http://api.example.com/auth/app-login/token' \
--header "Authorization: $API_KEY" \
--header "Content-Type: application/json" \
--data '{
"code": "string",
"code_verifier": "dBjftJeZ4CVP-mB92K27uhbUJU1p1r_wW1gFWFOEjXk"
}'
Request examples
{
"code": "string",
"code_verifier": "dBjftJeZ4CVP-mB92K27uhbUJU1p1r_wW1gFWFOEjXk"
}