Exchange an access token for a scoped v2 session

Non-interactive, server-to-server: verifies an access token issued by this deployment's OAuth authorization server (typ at+jwt, issuer, and an audience among the caller's resources) and issues a v2 session confined to its scope, with no refresh token. The caller authenticates with a client assertion bound to that token.

Body Params
string
required

access_token is an access token issued by this deployment's OAuth authorization
server, verified against its signing key, token type (at+jwt), issuer and the
caller's resource allowlist. An id_token is refused.

string

client_assertion is the caller's signed JWT (RFC 7523-style) proving it is a
configured exchange client; an exchange without one is refused.

Responses

Language
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json


  © 2026 Taurus SA. All rights reserved.