post
https://your-protect-instance.example.com/api/rest/v2/authentication/oidc/exchange
Non-interactive, server-to-server: verifies an access token issued by this deployment's OAuth authorization server (typ at+jwt, issuer, and an audience among the caller's resources) and issues a v2 session confined to its scope, with no refresh token. The caller authenticates with a client assertion bound to that token.