Skip to main content
POST
Exchanges an authorization code for an access token and an ID token, following the OIDC standard. Call it from your backend, because it needs the App Secret.
Send parameters as application/x-www-form-urlencoded and authenticate with your App ID and App Secret: HTTP Basic (client_secret_basic, recommended) or form fields (client_secret_post). Public clients without a secret (none) are not supported.

Request Body

string
default:"authorization_code"
required
Must be authorization_code. Refresh tokens are not issued.
string
required
The authorization code received on your redirect URI. Single-use, 5-minute lifetime.
string
required
Must exactly match the redirect URI used in the authorization request.
string
Required only if you sent code_challenge on the authorization request (PKCE, S256).

Response

string
Bearer token for the /userinfo endpoint. Valid for 10 minutes.
string
default:"Bearer"
Always Bearer.
number
Access token lifetime in seconds (600).
string
A signed JWT with authentication context only: sub, iss, aud, iat, exp, nonce, plus acr, hopae_loa, hopae_loa_label, and hopae_verification (provider_id, connection_id). Personal data is never in the ID token. Read it from /userinfo.
string
The granted scopes.

ID token claims

Decoded id_token payload
  • sub is the verification id, a new value for every verification, not a stable user identifier.
  • hopae_verification.provider_id and hopae_verification.connection_id identify the connection that ran (catalog ids). They are nested under hopae_verification, not top-level claims. There is no amr claim on v2 tokens.
  • iss is https://connect.hopae.com. Validate it, and verify aud against your App ID. Keys are at /jwks.
  • ID tokens are valid for 30 minutes.

Authorizations

Authorization
string
header
required

Basic authentication header of the form Basic <encoded-value>, where <encoded-value> is the base64-encoded string username:password.

Body

application/json
grant_type
enum<string>
required

Must be 'authorization_code'.

Available options:
authorization_code
code
string
required

The authorization code received after a successful verification.

client_id
string
required

Your application's Client ID.

client_secret
string

Your application's Client Secret. Required for confidential clients.

Response

Token exchange successful.

id_token
string

A JWT containing the user's verified claims.