OAuth token endpoint: token exchange (RFC 8693) or client credentials
The ffforms API token endpoint. It dispatches on grant_type:
urn:ietf:params:oauth:grant-type:token-exchange(RFC 8693): present an existing key assubject_tokento mint a short-lived child token for a sub-agent. The child can only narrow the parent (never escalate), is capped at one hour, never outlives the parent, and is revoked with it.client_credentials(RFC 6749 §4.4): a confidential client (created viaPOST /v1/clients) presentsclient_id+client_secretfor a one-hour access token scoped within its allowed grant. This is the autonomous machine-to-machine path.
Both authenticate by the credential in the body, so no Authorization header is needed. This endpoint is for the API’s own grants; the human authorization_code sign-in lives at the OAuth server’s /token.
Body·
required
application/json
An OAuth token request (token exchange or client credentials).
- grant
_type Discriminatorenumconst:urn:ietf:params:oauth:grant-type:token-exchangerequiredThe RFC 8693 token-exchange grant type.
values- urn:ietf:params:oauth:grant
-type:token -exchange
- Type: stringsubject
_token requiredThe API key to delegate from (the parent). Its secret,
fff_live_…. - Type: stringactormax length:200
Optional audit label for the sub-agent.
- Type: integerexpires
_in greater than:0max:3600Requested lifetime (s). Capped at one hour and the parent’s remaining lifetime. Defaults to 900.
- Type: stringscope
Space-delimited scopes to grant the child (a subset of the parent’s). Omit to inherit the parent grant.
- enumsubject
_token _type const:urn:ietf:params:oauth:token-type:access_tokenOptional; defaults to
access_token.values- urn:ietf:params:oauth:token
-type:access _token
Responses
- application/json
- application/problem+json
- application/problem+json
- application/problem+json
- application/problem+json
Request Example for post/v1/token
ffforms account token
{
"access_token": "fff_live_Qp9xYz0AbCdEf8Fh2Lm4",
"token_type": "Bearer",
"expires_in": 900,
"scope": "submissions:read",
"issued_token_type": "urn:ietf:params:oauth:token-type:access_token"
}