Exchange one-time code for JWT tokens

POST /auth/oidc/exchange

The frontend or CLI calls this endpoint with a one-time code received from the OIDC callback to obtain local JWT access and refresh tokens.

application/json

Body Required

One-time code and optional PKCE verifier

  • code string Required

    Code is the one-time code received from the OIDC callback.

  • code_verifier string

    CodeVerifier is the optional PKCE code_verifier that redeems a code minted with a CLI-supplied code_challenge (browser login). Omitted by UI logins and older CLIs.

Responses

  • 200 application/json

    JWT tokens

    Hide response attributes Show response attributes object
    • access_token string
    • atlas_connection_status string

      Values are connected, declined, or failed.

    • refresh_token string
    • token_type string
  • 400 application/json

    Bad Request

    Additional properties are allowed.

  • 401 application/json

    Unauthorized

    Additional properties are allowed.

  • 503 application/json

    Service Unavailable

    Additional properties are allowed.

POST /auth/oidc/exchange
curl \
 --request POST 'https://agentengine.mongodb.com/auth/oidc/exchange' \
 --header "Authorization: $API_KEY" \
 --header "Content-Type: application/json" \
 --data '{
  "code": "string",
  "code_verifier": "string"
}'
Request examples
{
  "code": "string",
  "code_verifier": "string"
}
Response examples (200)
{
  "access_token": "string",
  "atlas_connection_status": "connected",
  "refresh_token": "string",
  "token_type": "string"
}
Response examples (400)
{}
Response examples (401)
{}
Response examples (503)
{}