OAuth token endpoint: token exchange (RFC 8693) or client credentials

​

The ffforms API token endpoint. It dispatches on grant_type:

  • urn:ietf:params:oauth:grant-type:token-exchange (RFC 8693): present an existing key as subject_token to mint a short-lived child token for a sub-agent. The child can only narrow the parent (never escalate), is capped at one hour, never outlives the parent, and is revoked with it.
  • client_credentials (RFC 6749 §4.4): a confidential client (created via POST /v1/clients) presents client_id + client_secret for a one-hour access token scoped within its allowed grant. This is the autonomous machine-to-machine path.

Both authenticate by the credential in the body, so no Authorization header is needed. This endpoint is for the API’s own grants; the human authorization_code sign-in lives at the OAuth server’s /token.

Body·
required
application/json

An OAuth token request (token exchange or client credentials).

    • grant_type
      Discriminator
      enum
      const:  
      urn:ietf:params:oauth:grant-type:token-exchange
      required

      The RFC 8693 token-exchange grant type.

      values
      • urn:ietf:params:oauth:grant-type:token-exchange
    • subject_token
      Type: string
      required

      The API key to delegate from (the parent). Its secret, fff_live_….

    • actor
      Type: string
      max length:  
      200

      Optional audit label for the sub-agent.

    • expires_in
      Type: integer
      greater than:  
      0
      max:  
      3600

      Requested lifetime (s). Capped at one hour and the parent’s remaining lifetime. Defaults to 900.

    • scope
      Type: string

      Space-delimited scopes to grant the child (a subset of the parent’s). Omit to inherit the parent grant.

    • subject_token_type
      enum
      const:  
      urn:ietf:params:oauth:token-type:access_token

      Optional; defaults to access_token.

      values
      • urn:ietf:params:oauth:token-type:access_token
Responses
  • application/json
  • application/problem+json
  • application/problem+json
  • application/problem+json
  • application/problem+json
Request Example for post/v1/token
ffforms account token
{
  "access_token": "fff_live_Qp9xYz0AbCdEf8Fh2Lm4",
  "token_type": "Bearer",
  "expires_in": 900,
  "scope": "submissions:read",
  "issued_token_type": "urn:ietf:params:oauth:token-type:access_token"
}