---
title: "token (Authorization Code Exchange)"
url: "https://developer.pxg.konera.com/apis/number-verification-v1/versions/1554527f-4237-4b00-a8d4-a6b8d30bda00/operations/auth-v1_token"
---

> Full API specification: https://developer.pxg.konera.com/apis/number-verification-v1/versions/1554527f-4237-4b00-a8d4-a6b8d30bda00.md

# token (Authorization Code Exchange)

`POST` `/api/auth/v1/token`

Operation ID: `auth-v1_token`

OAuth 2.0 token endpoint to exchange authorization code for access token (CAMARA style).

## Request body (required)

Content types: `application/x-www-form-urlencoded`

## Responses

- `200` - OK
- `400` - Bad request
- `401` - Unauthorized
- `403` - Forbidden
- `429` - Too Many Requests
- `500` - Internal server error
- `503` - Service unavailable

## OpenAPI definition

```yaml
openapi: 3.0.3
info:
  title: Number Verification API
  version: 1.0.0
servers:
  - url: https://api.pxg.konera.com/camara
    description: Production CAMARA API Gateway
paths:
  /api/auth/v1/token:
    post:
      tags:
        - Number Verification V1
      summary: token (Authorization Code Exchange)
      operationId: auth-v1_token
      description: OAuth 2.0 token endpoint to exchange authorization code for access
        token (CAMARA style).
      security: []
      requestBody:
        required: true
        content:
          application/x-www-form-urlencoded:
            schema:
              $ref: "#/components/schemas/TokenRequest"
      responses:
        "200":
          description: OK
          content:
            application/json:
              schema:
                $ref: "#/components/schemas/TokenResponse"
        "400":
          $ref: "#/components/responses/BadRequest"
        "401":
          $ref: "#/components/responses/Unauthorized"
        "403":
          $ref: "#/components/responses/Forbidden"
        "429":
          $ref: "#/components/responses/TooManyRequests"
        "500":
          $ref: "#/components/responses/InternalServerError"
        "503":
          $ref: "#/components/responses/ServiceUnavailable"
security: []
components:
  schemas:
    TokenRequest:
      type: object
      required:
        - grant_type
        - code
        - redirect_uri
        - client_id
        - client_secret
      properties:
        grant_type:
          type: string
          enum:
            - authorization_code
          example: authorization_code
        code:
          type: string
          description: Authorization code received from authorize endpoint
        redirect_uri:
          type: string
          format: uri
          description: Must match the redirect URI used in the authorize request
        client_id:
          type: string
          description: Client identifier
        client_secret:
          type: string
          description: Client secret
    TokenResponse:
      type: object
      required:
        - access_token
        - token_type
        - expires_in
        - scope
      properties:
        access_token:
          type: string
          description: Access token for API calls
        token_type:
          type: string
          enum:
            - Bearer
          example: Bearer
        expires_in:
          type: integer
          description: Token expiration time in seconds
          example: 3600
        scope:
          type: string
          description: Granted scopes
          example: openid number-verification:verify
        refresh_token:
          type: string
          description: Refresh token if offline_access was requested
        id_token:
          type: string
          description: OpenID Connect ID token if openid scope was requested
    Error:
      type: object
      required:
        - status
        - code
        - message
      properties:
        status:
          type: integer
          example: 400
        code:
          type: string
          example: INVALID_ARGUMENT
        message:
          type: string
          example: Invalid request
  responses:
    BadRequest:
      description: Bad request
      content:
        application/json:
          schema:
            $ref: "#/components/schemas/Error"
    Unauthorized:
      description: Unauthorized
      content:
        application/json:
          schema:
            $ref: "#/components/schemas/Error"
    Forbidden:
      description: Forbidden
      content:
        application/json:
          schema:
            $ref: "#/components/schemas/Error"
    TooManyRequests:
      description: Too Many Requests
      content:
        application/json:
          schema:
            $ref: "#/components/schemas/Error"
    InternalServerError:
      description: Internal server error
      content:
        application/json:
          schema:
            $ref: "#/components/schemas/Error"
    ServiceUnavailable:
      description: Service unavailable
      content:
        application/json:
          schema:
            $ref: "#/components/schemas/Error"
```
