tencent cloud

Tencent OneID Identity Security

PKCE Authorization Code Mode

Download
Focus Mode
Font Size
Last updated: 2026-08-26 15:36:23
AI-Translated

API Description

After obtaining the code returned by the authentication portal via the PKCE authorization code mode, the application system calls this API to obtain the Access Token and ID Token, thereby completing the login.

Supported Application Types

Web applications, single-page applications, and mobile apps.

Request Method

POST

Request path

/oauth2/token

Request Content-Type

application/x-www-form-urlencoded

Request Example

POST /oauth2/token HTTP/1.1
Host: sample.portal.tencentciam.com
Content-Type: application/x-www-form-urlencoded

client_id=TENANT_CLIENT_ID&grant_type=authorization_code&code=MOCK_CODE&redirect_uri=https%3A%2F%2Fexample.com%2Fcallback&code_verifier=MOCK_CODE_VERIFIER

Request Parameters

Parameter
No
Description
client_id
false
The application's client_id. It must match the one used when authorization is obtained.
grant_type
false
Enter the fixed value authorization_code.
code
false
The authorization code returned when authorization is obtained.
redirect_uri
false
The redirect address after successful authorization. It must match the address specified when authorization is obtained.
code_verifier
false
The PKCE code_verifier. It must match the code_verifier used to generate the code_challenge when authorization is obtained.

Normal Response Example

HTTP/1.1 200 OK
Content-Type: application/json;charset=UTF-8

{
"access_token" : "eyJraWQiOiJkNDliYzUwNS01NTcyLTRlZDYtOWU0OC0zODhjM2Q0NGJiNDYiLCJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJzdWIiOiJNT0NLX1VTRVJOQU1FIiwiYXVkIjoiVEVOQU5UX0NMSUVOVF9JRCIsIm5iZiI6MTYzNjQ0OTIzMiwic2NvcGUiOlsib3BlbmlkIl0sImlzcyI6Imh0dHBzOlwvXC9URU5BTlQuUE9SVEFMLkRPTUFJTiIsImV4cCI6MTYzNjQ0OTUzMiwiaWF0IjoxNjM2NDQ5MjMyLCJqdGkiOiI0NjkyNTUxMC1mNjY0LTQzNTktODIyYS1jMTdiNTlmNzNhOGUifQ.mmM6iEiGCLIURqaKaJV_LbddUP1i5wCJMJvuasM8i6Wu_Ynix0W_EeghvMcQ94QvLhNYq2KshGQlkl0N5186KCqpHpG6z2ZXbuP35oY4yRFNvhqWOt8drvyxw13aVfehk1_KPLLDgrKGmHTUgxNDvssQq1u6Xd7QxPz0_d0jnaosl78pIO_tV-auGMhYQo6SHHMbFHgJLYBlPUq81eBknqbu8W9Omr4FuDmzlr9VFI4grJ_guxlUuri8lx-C4mRtSbg6bfUYlH7PuAM8bDfaOZ_qhAQ9-KTYF-ZiShDnuJMlVz0u_97ky5kNm_IUOrH6XzWfGL8MboYLagxOHmzNMQ",
"refresh_token" : "8FuXWpwMZI9oA8ASvCUrqap61N7RvPON6DjWFk-Saiv4dOR8y2tNf9eKf36woAaWYKwW99bpBAQVNWA7P8yM9jiBiGcix42ttYzvRoeMoEBoqYInBgnNMC8jTRTrKDEq",
"scope" : "openid",
"id_token" : "eyJraWQiOiJkNDliYzUwNS01NTcyLTRlZDYtOWU0OC0zODhjM2Q0NGJiNDYiLCJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJzdWIiOiJNT0NLX1VTRVJOQU1FIiwiYXVkIjoiVEVOQU5UX0NMSUVOVF9JRCIsImF6cCI6IlRFTkFOVF9DTElFTlRfSUQiLCJpc3MiOiJodHRwczpcL1wvVEVOQU5ULlBPUlRBTC5ET01BSU4iLCJleHAiOjE2MzY0NTEwMzIsImlhdCI6MTYzNjQ0OTIzMiwianRpIjoiMGMzODNiZTktOGFiNy00YzEwLTg5NWQtMzYwNjgzODg3MmZiIn0.i4Zywl6O5KF7iiivV-8d4Yok7CZr_eQNI8mTS3BkaRCIKiMzXJ55-T55XEonOViUE7s_Z4eMlyInm5-oLmk36NXrkO460LHEwxr8o5BlAnMhC4bd7xX3U3JrQISi6CpJxEn0UXXfJrtHnmR-yxAGNLFkoijM_qV1KWe6Y_OxxKe4FPfM2PwjYACt-XQgs4JsJOQk_UiSnHnvyvbpWTB8ZZriIwwxrNErZxdr09HBWhsQQ5fjJNviSilNLKD5fYYMz0yhl-YxDgMJ7s9tnfpDsNXyX25VpFtjdL4L13d1VAMPs2F5fTFBHX-p9LjoqF2sIJFEBbapgOX5EO-E_v1IFQ",
"token_type" : "Bearer",
"expires_in" : 299
}

Response Parameters

Parameter
Data Type
Description
access_token
String
OAuth 2.0 Access Token (JWT).
refresh_token
String
OAuth 2.0 Refresh Token.
scope
String
The Scope of the Access Token.
id_token
String
OIDC ID Token (JWT).
token_type
String
The Token type is currently set to the fixed value Bearer.
expires_in
Number
The validity period of the Access Token, in seconds.
Note:
IDSEC returns the ID Token in JWT format. To decrypt and validate the ID Token, see the OIDC official documentation. Alternatively, you can directly use relevant development libraries to complete the decryption and validation. The public key required for validation is obtained by calling the Get JWT Public Key API.

Exception Response Example

The client_id parameter is missing or incorrect.
HTTP/1.1 400 Bad Request
Content-Type: application/json;charset=UTF-8
{
"error" : "invalid_request"
}
The client_id does not match the one used when authorization and the Token are obtained.
HTTP/1.1 401 Unauthorized
Content-Type: application/json;charset=UTF-8
{
"error" : "invalid_client"
}
The grant_type parameter is incorrect.
HTTP/1.1 401 Unauthorized
The code parameter is incorrect.
HTTP/1.1 401 Unauthorized
Content-Type: application/json;charset=UTF-8

{
"error" : "invalid_client"
}
The code_verifier parameter is incorrect.
HTTP/1.1 401 Unauthorized
Content-Type: application/json;charset=UTF-8
{
"error" : "invalid_client"
}


Help and Support

Was this page helpful?

Help us improve! Rate your documentation experience in 5 mins.

Feedback