curl --request POST \
--url https://public-api.staging.workchats.com/oauth/token \
--header 'Authorization: Basic <encoded-value>' \
--header 'Content-Type: application/json' \
--data '
{
"code": "<string>",
"grant_type": "authorization_code",
"redirect_uri": "<string>",
"client_id": "<string>",
"client_secret": "<string>"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Basic <encoded-value>', 'Content-Type': 'application/json'},
body: JSON.stringify({
code: '<string>',
grant_type: 'authorization_code',
redirect_uri: '<string>',
client_id: '<string>',
client_secret: '<string>'
})
};
fetch('https://public-api.staging.workchats.com/oauth/token', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://public-api.staging.workchats.com/oauth/token"
payload = {
"code": "<string>",
"grant_type": "authorization_code",
"redirect_uri": "<string>",
"client_id": "<string>",
"client_secret": "<string>"
}
headers = {
"Authorization": "Basic <encoded-value>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"access_token": "wc_bot_live_0Xa9…",
"bot_user_id": "usr_8a1d2c3e-4b5f-4a6b-8c7d-9e0f1a2b3c4d",
"scope": "users:read users:read.email conversations:read messages:write",
"token_type": "Bearer",
"workspace": {
"id": "cmp_3f0c1b9e-5d0a-4a57-9a53-2f4f1c9d6b10",
"name": "Corpwise"
}
}{
"error": {
"code": "token_revoked",
"message": "The token has been revoked."
},
"ok": false,
"request_id": "F7p0mJcXk3tq2x0AAAAB"
}{
"error": {
"code": "token_revoked",
"message": "The token has been revoked."
},
"ok": false,
"request_id": "F7p0mJcXk3tq2x0AAAAB"
}{
"error": {
"code": "token_revoked",
"message": "The token has been revoked."
},
"ok": false,
"request_id": "F7p0mJcXk3tq2x0AAAAB"
}{
"error": {
"code": "token_revoked",
"message": "The token has been revoked."
},
"ok": false,
"request_id": "F7p0mJcXk3tq2x0AAAAB"
}{
"error": {
"code": "token_revoked",
"message": "The token has been revoked."
},
"ok": false,
"request_id": "F7p0mJcXk3tq2x0AAAAB"
}Exchange an authorization code for a bot token
Redeems the code the consent screen redirected with. Installs the App
into the approving admin’s company, or reconnects an existing
installation with the same bot user, and returns a new bot token. Any
earlier token of the installation stops working.
The token does not expire, so the response has no expires_in or
refresh_token. Codes are single-use and expire 10 minutes after
approval. Redeeming a used code again is invalid_grant and leaves the
token it already returned working, so retrying a timed-out exchange is
safe.
curl --request POST \
--url https://public-api.staging.workchats.com/oauth/token \
--header 'Authorization: Basic <encoded-value>' \
--header 'Content-Type: application/json' \
--data '
{
"code": "<string>",
"grant_type": "authorization_code",
"redirect_uri": "<string>",
"client_id": "<string>",
"client_secret": "<string>"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Basic <encoded-value>', 'Content-Type': 'application/json'},
body: JSON.stringify({
code: '<string>',
grant_type: 'authorization_code',
redirect_uri: '<string>',
client_id: '<string>',
client_secret: '<string>'
})
};
fetch('https://public-api.staging.workchats.com/oauth/token', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://public-api.staging.workchats.com/oauth/token"
payload = {
"code": "<string>",
"grant_type": "authorization_code",
"redirect_uri": "<string>",
"client_id": "<string>",
"client_secret": "<string>"
}
headers = {
"Authorization": "Basic <encoded-value>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"access_token": "wc_bot_live_0Xa9…",
"bot_user_id": "usr_8a1d2c3e-4b5f-4a6b-8c7d-9e0f1a2b3c4d",
"scope": "users:read users:read.email conversations:read messages:write",
"token_type": "Bearer",
"workspace": {
"id": "cmp_3f0c1b9e-5d0a-4a57-9a53-2f4f1c9d6b10",
"name": "Corpwise"
}
}{
"error": {
"code": "token_revoked",
"message": "The token has been revoked."
},
"ok": false,
"request_id": "F7p0mJcXk3tq2x0AAAAB"
}{
"error": {
"code": "token_revoked",
"message": "The token has been revoked."
},
"ok": false,
"request_id": "F7p0mJcXk3tq2x0AAAAB"
}{
"error": {
"code": "token_revoked",
"message": "The token has been revoked."
},
"ok": false,
"request_id": "F7p0mJcXk3tq2x0AAAAB"
}{
"error": {
"code": "token_revoked",
"message": "The token has been revoked."
},
"ok": false,
"request_id": "F7p0mJcXk3tq2x0AAAAB"
}{
"error": {
"code": "token_revoked",
"message": "The token has been revoked."
},
"ok": false,
"request_id": "F7p0mJcXk3tq2x0AAAAB"
}Authorizations
The App's client_id and client_secret, for the OAuth endpoints
Body
Code exchange
An authorization-code exchange. Send client_id and client_secret here or as HTTP Basic credentials.
Response
The bot token
A non-expiring bot token for the installation.