Get Access Token and Refresh Token
Use this endpoint to obtain an access token and a refresh token using an authorization code,
or to refresh an expired access token using a refresh token.
To get an access token (first time):
Set grant_type=authorization_code and provide the code parameter.
To refresh an access token:
Set grant_type=refresh_token and provide the refresh_token parameter.
Access tokens are valid for 1 hour.
Endpoint
Request URL
https://cpaas.zoho.com/v1.1/oauth/v2/token Copied!
Request Parameters
- Query Parameters
The Client ID generated from the Zoho API Console.
The Client Secret generated from the Zoho API Console.
The grant type. Use authorization_code for first-time token generation or refresh_token to refresh an expired token.
The authorization code generated from the Zoho API Console Self Client. Required when grant_type is authorization_code.
The refresh token received during first-time token generation. Required when grant_type is refresh_token.
Sample Request
curl --request POST \
--url 'https://cpaas.zoho.com/v1.1/oauth/v2/token?client_id=1000.XXXXXXXXXXXX&client_secret=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx&grant_type=authorization_code&code=1000.abc123xyz...&refresh_token=1000.refresh.abc123xyz...'Response Parameters
- HTTP code 200
Response Body - application/json
Show Sub-Attributes
- HTTP code 400
Response Body - application/json
Show Sub-Attributes
Sample Response: HTTP 200
{
"access_token": "1000.xxxx.xxxx",
"refresh_token": "1000.yyyy.yyyy",
"api_domain": "https://www.zohoapis.com",
"token_type": "Bearer",
"expires_in": 3600
}
Sample Response: HTTP 400
{
"error": "invalid_code"
}
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.