# Exchange one-time code for JWT tokens **POST /auth/oidc/exchange** The frontend or CLI calls this endpoint with a one-time code received from the OIDC callback to obtain local JWT access and refresh tokens. ## Servers - https://agentengine.mongodb.com: https://agentengine.mongodb.com () ## Authentication methods - Bearer auth ## Parameters ### Body: application/json (object) One-time code and optional PKCE verifier - **code** (string) Code is the one-time code received from the OIDC callback. - **code_verifier** (string) CodeVerifier is the optional PKCE code_verifier that redeems a code minted with a CLI-supplied code_challenge (browser login). Omitted by UI logins and older CLIs. ## Responses ### 200 JWT tokens #### Body: application/json (object) - **access_token** (string) - **atlas_connection_status** (string) - **refresh_token** (string) - **token_type** (string) ### 400 Bad Request #### Body: application/json (object) object ### 401 Unauthorized #### Body: application/json (object) object ### 503 Service Unavailable #### Body: application/json (object) object [Powered by Bump.sh](https://bump.sh)