> ## Documentation Index
> Fetch the complete documentation index at: https://docs.costgraph.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# OAuth token endpoint

> Accepts application/x-www-form-urlencoded grant_type=authorization_code (code, redirect_uri, code_verifier, client_id) or grant_type=refresh_token (refresh_token, client_id). Confidential clients authenticate with client_secret_basic (HTTP Basic) or client_secret_post (client_id and client_secret form fields); public clients send no secret. An id_token is returned when the openid scope was granted. Errors follow RFC 6749.



## OpenAPI

````yaml /api-reference/costgraph/openapi.json post /api/v1/oauth/token
openapi: 3.0.0
info:
  description: Read and manage your CostGraph organization, spend, alerts, and settings.
  title: CostGraph API
  contact: {}
  version: '1.0'
servers:
  - url: https://api.costgraph.ai
security: []
tags:
  - name: ai
    x-group: AI
  - name: ai-serving
    x-group: AI serving
  - name: anomalies
    x-group: Anomalies
  - name: auth
    x-group: Auth
  - name: billing
    x-group: Billing
  - name: billing-export
    x-group: Billing export
  - name: budgets
    x-group: Budgets
  - name: ci
    x-group: CI
  - name: compute-recommendations
    x-group: Compute recommendations
  - name: config
    x-group: Config
  - name: cost
    x-group: Cost
  - name: gpus
    x-group: GPUs
  - name: graphai
    x-group: Graph AI
  - name: infracost
    x-group: Infracost
  - name: integrations
    x-group: Integrations
  - name: invitations
    x-group: Invitations
  - name: kubernetes-clusters
    x-group: Kubernetes clusters
  - name: marketplace
    x-group: Marketplace
  - name: network-requests
    x-group: Network requests
  - name: notifications
    x-group: Notifications
  - name: oauth
    x-group: OAuth
  - name: oauth-clients
    x-group: OAuth clients
  - name: opencost
    x-group: OpenCost
  - name: organization
    x-group: Audit log
  - name: organizations
    x-group: Organizations
  - name: placement-alternatives
    x-group: Placement alternatives
  - name: reports
    x-group: Reports
  - name: service-map
    x-group: Service map
  - name: settings
    x-group: Settings
  - name: sso
    x-group: Single sign-on
  - name: tenants
    x-group: Tenants
  - name: user
    x-group: Users
  - name: virtual-machines
    x-group: Virtual machines
  - name: virtual-tags
    x-group: Virtual tags
  - name: workflows
    x-group: Workflows
paths:
  /api/v1/oauth/token:
    post:
      tags:
        - oauth
      summary: OAuth token endpoint
      description: >-
        Accepts application/x-www-form-urlencoded grant_type=authorization_code
        (code, redirect_uri, code_verifier, client_id) or
        grant_type=refresh_token (refresh_token, client_id). Confidential
        clients authenticate with client_secret_basic (HTTP Basic) or
        client_secret_post (client_id and client_secret form fields); public
        clients send no secret. An id_token is returned when the openid scope
        was granted. Errors follow RFC 6749.
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/oauth.TokenResponse'
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/controllers.oauthErrorResponse'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/controllers.oauthErrorResponse'
components:
  schemas:
    oauth.TokenResponse:
      type: object
      properties:
        access_token:
          type: string
        expires_in:
          type: integer
        id_token:
          type: string
        refresh_token:
          type: string
        scope:
          type: string
        token_type:
          type: string
    controllers.oauthErrorResponse:
      type: object
      properties:
        error:
          type: string
        error_description:
          type: string

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.