Get Access Token and Refresh Token

Open in ChatGPT Open in ChatGPT to ask questions about this page
Open in Claude Open in Claude to ask questions about this page
Copy as MarkdownCopy this page as markdown to use with AI assistants
View as Markdown Open this page as markdown in a new tab

Use this endpoint to obtain an access token and a refresh token using an authorization code,
or to refresh an expired access token using a refresh token.

To get an access token (first time):
Set grant_type=authorization_code and provide the code parameter.

To refresh an access token:
Set grant_type=refresh_token and provide the refresh_token parameter.

Access tokens are valid for 1 hour.

Endpoint

Request URL

https://cpaas.zoho.com/v1.1/oauth/v2/token Copied!

Request Parameters

- Query Parameters

client_idstringMandatory

The Client ID generated from the Zoho API Console.

client_secretstringMandatory

The Client Secret generated from the Zoho API Console.

grant_typestringMandatory

The grant type. Use authorization_code for first-time token generation or refresh_token to refresh an expired token.

Allowed Values :
Show Values ▾
authorization_codeCopied!
refresh_tokenCopied!
Copied!Copy all as JSON Array
codestringOptional

The authorization code generated from the Zoho API Console Self Client. Required when grant_type is authorization_code.

refresh_tokenstringOptional

The refresh token received during first-time token generation. Required when grant_type is refresh_token.

Sample Request

Curl
Java
Python
Deluge
Copied!
curl --request POST \
  --url 'https://cpaas.zoho.com/v1.1/oauth/v2/token?client_id=1000.XXXXXXXXXXXX&client_secret=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx&grant_type=authorization_code&code=1000.abc123xyz...&refresh_token=1000.refresh.abc123xyz...'

Response Parameters

- HTTP code 200

Response Body - application/json
JSON Object
Show Sub-Attributes
access_tokenstring
refresh_tokenstring
api_domainstring
token_typestring
expires_ininteger

- HTTP code 400

Response Body - application/json
JSON Object
Show Sub-Attributes
errorstring

Sample Response: HTTP 200

Copied!
  {
    "access_token": "1000.xxxx.xxxx",
    "refresh_token": "1000.yyyy.yyyy",
    "api_domain": "https://www.zohoapis.com",
    "token_type": "Bearer",
    "expires_in": 3600
  }
                
▼ Show full

Sample Response: HTTP 400

Copied!
  {
    "error": "invalid_code"
  }
                
▼ Show full