> ## Documentation Index
> Fetch the complete documentation index at: https://moengage.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Generate Access Token

> Exchange the `client_id` and `client_secret` of an OAuth 2.0 API key for an access token and a refresh token.

The `client_id` is your Workspace ID, and the `client_secret` is the API key value that the dashboard displays once, when you create the key. The key must have **Authentication Type** set to **OAuth 2.0** on the API key dashboard, or the request fails with `ER012`.

To create the key, refer to [API Key Dashboard](/user-guide/settings/account/api-and-api-keys/api-key-dashboard). For the end-to-end integration, refer to [OAuth 2.0 Overview](/api/oauth/oauth-overview). To renew an access token without resending your API key, refer to [Refresh Access Token](/api/oauth/refresh-access-token).



## OpenAPI

````yaml /api/oauth/oauth.yaml post /v1/oauth/token
openapi: 3.0.3
info:
  title: MoEngage OAuth 2.0 API
  version: '1.0'
  description: >-
    API for generating and refreshing OAuth 2.0 access tokens used to
    authenticate requests to the MoEngage Public APIs.


    You exchange the credentials of an OAuth 2.0 API key for a short-lived
    access token, send that access token as a Bearer token on your API requests,
    and refresh the access token before the token expires.


    For the end-to-end setup, including creating the API key and calling the
    Public APIs, refer to [OAuth 2.0 Overview](/api/oauth/oauth-overview).
servers:
  - url: https://oauth2-{dc}.moengage.com
    description: OAuth Endpoint
    variables:
      dc:
        default: '01'
        enum:
          - '01'
          - '02'
          - '03'
          - '04'
          - '05'
          - '06'
          - '101'
        description: >-
          The 'dc' in the API Endpoint URL refers to the MoEngage Data Center
          (DC). MoEngage hosts each customer in a different DC. You can find
          your DC number and replace the value of 'dc' in the URL by referring
          to the DC and API endpoint mapping
          [here](/api/introduction#data-centers). Your MoEngage Data Center (DC)
          can be 01, 02, 03, 04, 05, 06, or 101.
security: []
tags:
  - name: OAuth
    description: >-
      Generate and refresh the OAuth 2.0 access tokens that authenticate your
      MoEngage Public API requests. For the end-to-end integration, refer to
      [OAuth 2.0 Overview](/api/oauth/oauth-overview).
paths:
  /v1/oauth/token:
    post:
      tags:
        - OAuth
      summary: Generate Access Token
      description: >-
        Exchange the `client_id` and `client_secret` of an OAuth 2.0 API key for
        an access token and a refresh token.


        The `client_id` is your Workspace ID, and the `client_secret` is the API
        key value that the dashboard displays once, when you create the key. The
        key must have **Authentication Type** set to **OAuth 2.0** on the API
        key dashboard, or the request fails with `ER012`.


        To create the key, refer to [API Key
        Dashboard](/user-guide/settings/account/api-and-api-keys/api-key-dashboard).
        For the end-to-end integration, refer to [OAuth 2.0
        Overview](/api/oauth/oauth-overview). To renew an access token without
        resending your API key, refer to [Refresh Access
        Token](/api/oauth/refresh-access-token).
      requestBody:
        required: true
        description: The form-encoded credentials for the client credentials grant.
        content:
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/TokenRequest'
            example:
              grant_type: client_credentials
              client_id: YOUR_WORKSPACE_ID
              client_secret: YOUR_API_KEY
      responses:
        '200':
          description: >-
            MoEngage issued an access token and a refresh token. Store both
            tokens. The refresh token stays valid for 30 days.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TokenSuccessResponse'
              example:
                status: SUCCESS
                data:
                  access_token: eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjoiUlN3Q2t6...
                  refresh_token: 550e8400-e29b-41d4-a716-446655440000
                  token_type: Bearer
                  expires_in: 900
        '400':
          description: >-
            A required form parameter is missing or holds an invalid value.


            | `error_type` | Cause | Resolution |

            | --- | --- | --- |

            | `ER018` | `grant_type` is missing or is not `client_credentials`.
            | Correct the parameter. |

            | `ER019` | `client_id` is missing. | Correct the parameter. |

            | `ER020` | `client_secret` is missing. | Correct the parameter. |
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthErrorResponse'
              example:
                status: FAILURE
                error_type: ER019
                reason: client_id is required.
        '401':
          description: >-
            MoEngage could not validate the credentials.


            | `error_type` | Cause | Resolution |

            | --- | --- | --- |

            | `ER011` | The `client_id` or `client_secret` is not valid. | Check
            both values. Regenerate the key if needed. |

            | `ER012` | The key exists but is not an OAuth 2.0 key. | Create a
            key with **Authentication Type** set to **OAuth 2.0**. |
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthErrorResponse'
              example:
                status: FAILURE
                error_type: ER011
                reason: Auth validation failed.
        '415':
          description: >-
            The request body used an unsupported media type. Send the request
            body in form-encoded format as `application/x-www-form-urlencoded`.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthErrorResponse'
        '429':
          description: >-
            The request exceeded the rate limit. Wait for the number of seconds
            given in the `Retry-After` response header, and then retry the
            request.
          headers:
            Retry-After:
              description: The number of seconds to wait before you retry the request.
              schema:
                type: integer
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthErrorResponse'
              example:
                status: FAILURE
                error_type: RATE_LIMIT_EXCEEDED
                reason: Too many requests.
      security: []
components:
  schemas:
    TokenRequest:
      type: object
      required:
        - grant_type
        - client_id
        - client_secret
      properties:
        grant_type:
          type: string
          enum:
            - client_credentials
          description: >-
            The OAuth 2.0 grant type. The supported value is
            `client_credentials`.
        client_id:
          type: string
          description: >-
            Your Workspace ID. The API key dashboard displays the Workspace ID
            at **Settings** > **Account** > **API keys**.
        client_secret:
          type: string
          description: >-
            The API key value. The dashboard displays the API key only once,
            when you create the key.
    TokenSuccessResponse:
      type: object
      properties:
        status:
          type: string
          description: >-
            The status of the request. The value is `SUCCESS` for a successful
            request.
          example: SUCCESS
        data:
          type: object
          properties:
            access_token:
              type: string
              description: >-
                The access token that you send as a Bearer token on your API
                requests.
            refresh_token:
              type: string
              description: >-
                The token that you exchange for new access tokens at [Refresh
                Access Token](/api/oauth/refresh-access-token). The refresh
                token is valid for 30 days.
            token_type:
              type: string
              description: The token type. The value is always `Bearer`.
              example: Bearer
            expires_in:
              type: integer
              description: >-
                The lifetime of the access token, in seconds. The value reflects
                the **Access token expiration (in minutes)** set on the API key.
              example: 900
    OAuthErrorResponse:
      type: object
      properties:
        status:
          type: string
          description: >-
            The status of the request. The value is `FAILURE` for a failed
            request.
          example: FAILURE
        error_type:
          type: string
          description: The MoEngage error code that identifies the cause of the failure.
        reason:
          type: string
          description: A human-readable description of the failure.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.