# Trade a browser login code for tokens **POST /auth/app-login/token** Exchange a one-time code minted through the browser for a new access and refresh token pair. The code can be used once, and only with the PKCE code verifier matching its challenge. The response has the same shape as a successful login and never sets cookies. ## Servers - http://api.example.com: http://api.example.com () ## Authentication methods - Jwt authorization ## Parameters ### Body: application/json (object) - **code** (string) One-time login code - **code_verifier** (string) PKCE code verifier (43 to 128 characters) ## Responses ### 200 Login successful ### 400 Unknown, expired or already used code, wrong verifier or inactive user [Powered by Bump.sh](https://bump.sh)