Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Parameter

Value

Note

grant_type

authorization_code

code

obtained from redirect uri query parameter from step 1

client_id

same value as client_id query parameter from step 1

client_secret

value provided by Everifin

redirect_uri

same value as redirect_uri query parameter from step 1

code_verifier

Optional, only necessary for PKCE. We use it to recompute the code_challenge and verify if it matches the original code_challenge in the authorization request.

...

Code Block
languagejson
{
    "access_token": "9f075bc8059dbc4203860f1857c8548cd705f3760ac0551577565e81de12e7472b62f47f8d6934dc5e05cebcf86ce399e2b5e27a4222a8e51925d25d1c389ba3",
    "expires_in": 15003600,
    "refresh_expires_in": 36002592000,
    "refresh_token": "faf0d3a7b234ae25e4ad1c9e13b39ba8c775cb4355342ab6e71d6fdb1776dc1adcd10cf62cfe9b7d9acb485b5205575d136cf4d0e81027766e8c6e18c9ba11e9",
    "token_type": "bearer",
    "id_token": "75cb4355342ab6e71d6fdb1776dc1adcd10cf62cfe9b7d9acb485b",
    "not-before-policy": 0,
    "session_state": "1c01ba2b-76b4-445c-9c56-1fdd4b7c38c7",
    "scope": "openid email profile"
}

...

Parameter

Value

Note

grant_type

refresh_token

client_id

same value as client_id query parameter from step 1

client_secret

Value provided by Everifin

refresh_token

value from “refresh_token” field on JSON response from step2

...