Authentication
Projects
Environments
Rows
Functions
Webhooks
Authentication
Create token
Exchange credentials for an access token and a refresh token.
POST
/v1/auth/token
Signs a user in with email and password, or exchanges an OAuth code, and returns a short-lived access token together with a refresh token.
Request body
grant_typestringrequiredOne of password or authorization_code.
emailstringoptionalRequired when grant_type is password.
passwordstringoptionalRequired when grant_type is password.
codestringoptionalThe OAuth code, required for authorization_code.
Response fields
access_tokenstringrequiredJWT valid for 15 minutes.
refresh_tokenstringrequiredOpaque token valid for 30 days.
expires_inintegerrequiredSeconds until the access token expires.
userobjectrequiredThe signed-in user: id, email, name.
Errors
invalid_grantThe credentials or code are wrong.
rate_limitedToo many requests. Retry after the number of seconds in Retry-After.
© 2026 Tessera, Inc.
Support
Status