Register & Issue tokens

Issues access/refresh tokens. The behaviour depends on the grant_type field.

grant_typeDescription
registerRegister a new standard account and receive tokens
register_minorRegister a junior/minor account (requires guardian email)
passwordResource Owner Password Credentials
refresh_tokenExchange a refresh token for a new access token
anonymousIssue tokens for an anonymous session
authorization_codeExchange an authorisation code (PKCE supported)
mfa_otpComplete MFA with a TOTP/OTP code
mfa_oobComplete MFA with an out-of-band code
mfa_recovery_codesComplete MFA with a recovery code

When MFA is required, the server responds with HTTP 401 and a body containing mfa_token and an mfa object instead of normal tokens.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Form Data
string
enum
required
string

Required for most grant types

string

Required for authorization_code (or use Basic Auth)

string

User email or username (password / register grants)

string

User password (password / register / register_minor grants)

string

Refresh token (refresh_token grant)

string

Authorization code (authorization_code grant) or OTP code (mfa_otp / mfa_recovery_codes)

string

Required for authorization_code grant

string

PKCE verifier (authorization_code grant)

string
string
string
string

Junior account email (register_minor)

string

Guardian email (register_minor)

string

Anonymous token to link (register grant)

string
string
string
uuid

MFA authenticator ID (mfa_otp)

string

Out-of-band code (mfa_oob)

boolean

Mark device as trusted (MFA grants)

uuid
string
enum
Allowed:
Responses

Language
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json