> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getsly.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# OAuth 2.0 token endpoint

> Exchange authorization code for access token, or refresh an existing token.



## OpenAPI

````yaml /api-reference/openapi.json post /v1/ucp/identity/token
openapi: 3.1.0
info:
  title: Sly API
  description: >-
    The Agentic Economy Platform — stablecoin payments, agent wallets,
    multi-protocol commerce, and AI agent orchestration.
  version: 1.0.0
  contact:
    name: Sly
    url: https://getsly.ai
    email: support@getsly.ai
servers:
  - url: https://api.getsly.ai/v1
    description: Production
  - url: https://sandbox.getsly.ai/v1
    description: Sandbox
security:
  - bearerAuth: []
paths:
  /v1/ucp/identity/token:
    post:
      tags:
        - UCP Identity
      summary: OAuth 2.0 token endpoint
      description: >-
        Exchange authorization code for access token, or refresh an existing
        token.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              oneOf:
                - type: object
                  properties:
                    grant_type:
                      type: string
                      enum:
                        - authorization_code
                    code:
                      type: string
                    client_id:
                      type: string
                    client_secret:
                      type: string
                    redirect_uri:
                      type: string
                      format: uri
                  required:
                    - grant_type
                    - code
                    - client_id
                    - client_secret
                    - redirect_uri
                - type: object
                  properties:
                    grant_type:
                      type: string
                      enum:
                        - refresh_token
                    refresh_token:
                      type: string
                    client_id:
                      type: string
                    client_secret:
                      type: string
                  required:
                    - grant_type
                    - refresh_token
                    - client_id
                    - client_secret
      responses:
        '200':
          description: Token
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthTokenResponse'
        '400':
          description: Invalid grant
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/Error'
                  - properties:
                      error:
                        type: string
                      code:
                        type: string
                      details: {}
      security:
        - bearerAuth: []
components:
  schemas:
    OAuthTokenResponse:
      type: object
      properties:
        access_token:
          type: string
        token_type:
          type: string
          enum:
            - Bearer
        expires_in:
          type: integer
        refresh_token:
          type: string
        scope:
          type: string
      required:
        - access_token
        - token_type
        - expires_in
        - scope
    Error:
      type: object
      properties:
        error:
          type: string
        code:
          type: string
        details: {}
        request_id:
          type: string
      required:
        - error
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        API key (pk_test_* or pk_live_*), JWT session, agent token (agent_*),
        Ed25519 session (sess_*), or portal token (portal_*).

````