Emite e renova tokens OAuth do MCP
POST/oauth/token
- Auth
- Richiede un token
Le descrizioni degli endpoint provengono dalla specifica dell’API e per ora sono in portoghese. L’interfaccia intorno è tradotta.
`grant_type=authorization_code` troca o código pelo par de tokens, conferindo o PKCE (`code_verifier`) e a `redirect_uri`. `grant_type=refresh_token` renova e **gira** o refresh token: reapresentar um já usado revoga a conexão inteira. Access token de 1 hora, refresh de 30 dias, ambos opacos e presos à conexão (membro + comunidade). Aceita `application/x-www-form-urlencoded` ou JSON. Limite de 60 por minuto por IP. Público.
Corpo della richiesta application/x-www-form-urlencoded
| Nome | Tipo | Descrizione |
|---|---|---|
grant_typeobbligatorio | authorization_code | refresh_token | |
client_idobbligatorio | string | |
client_secretfacoltativo | string | |
codefacoltativo | string | |
redirect_urifacoltativo | string | |
code_verifierfacoltativo | string | |
refresh_tokenfacoltativo | string | |
resourcefacoltativo | string |
Risposte
| Codice | Descrizione |
|---|---|
200 | `{ access_token, token_type: Bearer, expires_in, refresh_token, scope }`. |
400 | `{ error, error_description }` — `invalid_grant`, `invalid_request`, `unsupported_grant_type`. |
401 | `invalid_client`. |
Esempio con curl
curl -X POST "https://api.memberfy.net/oauth/token" \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"grant_type":"authorization_code","client_id":"string"}'