Hanzo
OpenapiIam

Exchanges what your application is holding for the tokens it needs — the…

Exchanges what your application is holding for the tokens it needs — the one-time code from a finished sign-in, a refresh token, or your own client…

POST /v1/iam/oauth/token

Addresshttps://api.hanzo.ai/v1/iam/oauth/token
MethodPOST
Operationpost_iam_oauth_token
AuthAuthorization: Bearer $HANZO_API_KEY

Exchanges what your application is holding for the tokens it needs — the one-time code from a finished sign-in, a refresh token, or your own client credentials when the caller is a program rather than a person.

A refresh returns a NEW refresh token and retires the one you sent. If a retired one is ever presented again the whole chain is revoked, on the assumption that a token which came back from the dead was copied — so a stolen refresh token buys an attacker one use and costs them the session.

Responses are never cached, by any hop.

Request

The document declares no body for POST /v1/iam/oauth/token. The handler is typed in cloud but its shape is not yet emitted, so the fields are not listed here — ask the MCP door's describe for post_iam_oauth_token, which answers from the running route.

Response

The document declares no response body for this operation. It answers 200 on success and the platform error shape on failure — see Errors.

Examples

hanzo iam oauth token

IAM API · All Hanzo APIs · Interactive reference

How is this guide?

On this page