> ## Documentation Index
> Fetch the complete documentation index at: https://doc.extole.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a managed token via authorization code

> Creates a managed access token by exchanging an OpenID Connect authorization code. Returns the created token.



## OpenAPI

````yaml /api-reference/management-expert.json post /v4/tokens/managed/openid-connect/authorization-code-flow
openapi: 3.0.1
info:
  description: >-
    Advanced configuration endpoints for Extole platform experts: campaign
    controllers, typed actions and triggers, advanced component types and
    facets, source mapping, report post-handlers, pre-handlers, and other expert
    configuration surfaces not included in the standard Management API.
  title: Management Expert API
  version: '1.0'
servers:
  - description: Production
    url: https://api.extole.io
security:
  - HEADER: []
  - QUERY: []
  - COOKIE: []
tags:
  - name: Authentication
  - name: Campaign Controllers
  - name: Campaign Controllers Actions
  - name: Campaign Controllers Triggers
  - name: Campaign Flow Steps
  - name: Components
  - name: Components Grants
  - name: Components Subscriptions
  - name: Components Types
  - name: Content
  - name: Debug
  - name: Domains
  - name: Email
  - name: Event Prehandlers
  - name: Events
  - name: Javascript Core Extensions
  - name: Persons
  - name: Profiles
  - name: Report Schedules
  - name: Report Types
  - name: Reporting
  - name: Security Keys
  - name: Settings
paths:
  /v4/tokens/managed/openid-connect/authorization-code-flow:
    post:
      tags:
        - Authentication
      summary: Create a managed token via authorization code
      description: >-
        Creates a managed access token by exchanging an OpenID Connect
        authorization code. Returns the created token.
      operationId: createManagedTokenViaAuthorizationCode
      parameters:
        - in: header
          name: X-CSRF-TOKEN
          schema:
            type: string
        - in: header
          name: X-NONCE
          schema:
            type: string
      requestBody:
        content:
          application/json:
            example:
              code: code
              duration_seconds: 1
              name: name
              scopes:
                - BACKEND
              state: state
            schema:
              $ref: '#/components/schemas/AuthCodeManagedAccessTokenCreationRequest'
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ManagedAccessTokenResponse'
          description: Successful response
        '400':
          content:
            application/json:
              examples:
                binding_error:
                  $ref: '#/components/examples/binding_error'
                invalid_duration:
                  $ref: '#/components/examples/invalid_duration'
                invalid_json:
                  $ref: '#/components/examples/invalid_json'
                invalid_parameter:
                  $ref: '#/components/examples/invalid_parameter'
                maximum_name_length:
                  $ref: '#/components/examples/maximum_name_length'
                missing_request_body:
                  $ref: '#/components/examples/missing_request_body'
                no_such_managed_token:
                  $ref: '#/components/examples/no_such_managed_token'
              schema:
                $ref: '#/components/schemas/RestExceptionResponse'
          description: Bad Request
        '401':
          content:
            application/json:
              examples:
                method_unauthorized:
                  $ref: '#/components/examples/method_unauthorized'
              schema:
                $ref: '#/components/schemas/RestExceptionResponse'
          description: Unauthorized
        '402':
          content:
            application/json:
              examples:
                payment_required:
                  $ref: '#/components/examples/payment_required'
              schema:
                $ref: '#/components/schemas/RestExceptionResponse'
          description: Payment Required
        '403':
          content:
            application/json:
              examples:
                access_denied:
                  $ref: '#/components/examples/access_denied'
                account_disabled:
                  $ref: '#/components/examples/account_disabled'
                account_locked:
                  $ref: '#/components/examples/account_locked'
                authorization_code_missing_code:
                  $ref: '#/components/examples/authorization_code_missing_code'
                authorization_code_missing_csrf_token:
                  $ref: '#/components/examples/authorization_code_missing_csrf_token'
                authorization_code_missing_nonce:
                  $ref: '#/components/examples/authorization_code_missing_nonce'
                authorization_code_missing_state:
                  $ref: '#/components/examples/authorization_code_missing_state'
                authorization_code_response_invalid:
                  $ref: '#/components/examples/authorization_code_response_invalid'
                expired_credentials:
                  $ref: '#/components/examples/expired_credentials'
                invalid_credentials:
                  $ref: '#/components/examples/invalid_credentials'
                method_unauthorized:
                  $ref: '#/components/examples/method_unauthorized'
                missing_access_token:
                  $ref: '#/components/examples/missing_access_token'
                missing_credentials:
                  $ref: '#/components/examples/missing_credentials'
              schema:
                $ref: '#/components/schemas/RestExceptionResponse'
          description: Forbidden
        '415':
          content:
            application/json:
              examples:
                unsupported_media_type:
                  $ref: '#/components/examples/unsupported_media_type'
              schema:
                $ref: '#/components/schemas/RestExceptionResponse'
          description: Unsupported Media Type
        '429':
          content:
            application/json:
              examples:
                too_many_requests:
                  $ref: '#/components/examples/too_many_requests'
              schema:
                $ref: '#/components/schemas/RestExceptionResponse'
          description: Too Many Requests
components:
  schemas:
    AuthCodeManagedAccessTokenCreationRequest:
      properties:
        code:
          type: string
        duration_seconds:
          format: int64
          nullable: true
          type: integer
        name:
          type: string
        scopes:
          items:
            enum:
              - BACKEND
              - CLIENT_ADMIN
              - CLIENT_REPORT_DOWNLOAD
              - CLIENT_SUPERUSER
              - ONE_TIME
              - PASSWORD_RESET
              - UPDATE_PROFILE
              - USER_SUPPORT
              - VERIFIED_CONSUMER
            type: string
          nullable: true
          type: array
          uniqueItems: true
        state:
          type: string
      required:
        - code
        - duration_seconds
        - name
        - scopes
        - state
      type: object
    ManagedAccessTokenResponse:
      properties:
        access_token:
          type: string
        access_token_id:
          type: string
        access_token_response:
          $ref: '#/components/schemas/AccessTokenResponse'
        client_id:
          type: string
        create_date:
          $ref: '#/components/schemas/ZonedDateTime'
        created_at:
          format: int64
          type: integer
        expire_date:
          $ref: '#/components/schemas/ZonedDateTime'
        expires_in:
          format: int64
          type: integer
        name:
          type: string
      required:
        - access_token
        - access_token_id
        - access_token_response
        - client_id
        - create_date
        - created_at
        - expire_date
        - expires_in
        - name
      type: object
    RestExceptionResponse:
      description: Represents the API error response
      properties:
        code:
          description: Specific error code for this error type, documented per endpoint
          type: string
        http_status_code:
          description: >-
            HTTP status code that was returned with this error, useful if client
            get response code
          format: int32
          type: integer
        message:
          description: User readable English description of the error
          type: string
        parameters:
          additionalProperties:
            description: >-
              Attributes related to the error, varies be error code, documented
              per endpoint
            type: object
          description: >-
            Attributes related to the error, varies be error code, documented
            per endpoint
          type: object
        unique_id:
          description: >-
            Unique id associated with this error, useful for discussions with
            Extole
          type: string
      required:
        - code
        - http_status_code
        - message
        - parameters
        - unique_id
      type: object
    AccessTokenResponse:
      description: >-
        Access-token metadata returned by `POST /v4/tokens`, `POST
        /v4/tokens/openid-connect/authorization-code-flow`, `GET /v4/tokens`,
        `GET /v4/tokens/{token}`, and `PUT /v4/tokens/exchange/{token}`. Pass
        `access_token` in the `Authorization` header (`Bearer ...`) on
        subsequent requests.
      properties:
        access_token:
          description: >-
            Token string. Send as `Authorization: Bearer <access_token>` on
            subsequent requests, or as the `access_token` query parameter /
            `extole_token` cookie.
          type: string
        client_id:
          description: >-
            Stable Extole identifier for the client (tenant) this token
            authenticates against.
          type: string
        expires_in:
          description: >-
            Seconds until this token expires. Once expired, requests using it
            return `401 invalid_access_token`; rotate via `PUT
            /v4/tokens/exchange/{token}` before expiry to keep long-lived
            integrations alive.
          format: int64
          type: integer
        identity_id:
          description: >-
            Stable Extole identifier for the identity (user, managed identity,
            or resource) that this token represents.
          type: string
        person_id:
          deprecated: true
          description: >-
            Deprecated alias for `identity_id`. New integrations should use
            `identity_id`.
          type: string
        scopes:
          description: >-
            Authorization scopes granted to this token. Determines which API
            operations the token may invoke.
          items:
            description: >-
              Authorization scopes granted to this token. Determines which API
              operations the token may invoke.
            enum:
              - BACKEND
              - CLIENT_ADMIN
              - CLIENT_REPORT_DOWNLOAD
              - CLIENT_SUPERUSER
              - ONE_TIME
              - PASSWORD_RESET
              - UPDATE_PROFILE
              - USER_SUPPORT
              - VERIFIED_CONSUMER
            type: string
          type: array
          uniqueItems: true
        type:
          description: >-
            Authentication shape backing the token. `USER` represents a human
            dashboard user, `MANAGED` an OAuth-style managed identity, and
            `RESOURCE` a scoped per-resource token.
          enum:
            - MANAGED
            - RESOURCE
            - USER
          type: string
      type: object
    ZonedDateTime:
      description: >-
        [RFC 3339](https://datatracker.ietf.org/doc/html/rfc3339#section-5.6) or
        [RFC 9557](https://datatracker.ietf.org/doc/html/rfc9557#section-4)
        date-time with a numeric [UTC
        offset](https://datatracker.ietf.org/doc/html/rfc3339#section-5.6) and
        an optional [IANA
        time-zone](https://datatracker.ietf.org/doc/html/rfc9557#section-4)
        suffix in square brackets. Precision up to milliseconds.
      example: '2025-10-24T02:00:00-07:00'
      pattern: >-
        ^\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}(\.\d{1,3})?(Z|[+-](?:[01][0-9]|2[0-3]):[0-5][0-9])(\[[^\]]+\])?$
      type: string
  examples:
    binding_error:
      summary: binding_error
      value:
        code: binding_error
        http_status_code: 400
        message: Argument is not of the expected type
        parameters: {}
        unique_id: 00000000-0000-0000-0000-000000000000
    invalid_duration:
      summary: invalid_duration
      value:
        code: invalid_duration
        http_status_code: 400
        message: >-
          The requested duration for this token must end within the first ten
          millenium
        parameters: {}
        unique_id: 00000000-0000-0000-0000-000000000000
    invalid_json:
      summary: invalid_json
      value:
        code: invalid_json
        http_status_code: 400
        message: JSON is invalid
        parameters: {}
        unique_id: 00000000-0000-0000-0000-000000000000
    invalid_parameter:
      summary: invalid_parameter
      value:
        code: invalid_parameter
        http_status_code: 400
        message: Parameter is invalid.
        parameters: {}
        unique_id: 00000000-0000-0000-0000-000000000000
    maximum_name_length:
      summary: maximum_name_length
      value:
        code: maximum_name_length
        http_status_code: 400
        message: Name cannot be null, empty or blank and cannot be too long
        parameters: {}
        unique_id: 00000000-0000-0000-0000-000000000000
    missing_request_body:
      summary: missing_request_body
      value:
        code: missing_request_body
        http_status_code: 400
        message: Missing request body
        parameters: {}
        unique_id: 00000000-0000-0000-0000-000000000000
    no_such_managed_token:
      summary: no_such_managed_token
      value:
        code: no_such_managed_token
        http_status_code: 400
        message: The access_token provided is could not be found.
        parameters: {}
        unique_id: 00000000-0000-0000-0000-000000000000
    method_unauthorized:
      summary: method_unauthorized
      value:
        code: method_unauthorized
        http_status_code: 401
        message: Unauthorized access to this endpoint
        parameters: {}
        unique_id: 00000000-0000-0000-0000-000000000000
    payment_required:
      summary: payment_required
      value:
        code: payment_required
        http_status_code: 402
        message: The access_token provided is associated with an unpaid account.
        parameters: {}
        unique_id: 00000000-0000-0000-0000-000000000000
    access_denied:
      summary: access_denied
      value:
        code: access_denied
        http_status_code: 403
        message: >-
          The access_token provided is not permitted to access the specified
          resource.
        parameters: {}
        unique_id: 00000000-0000-0000-0000-000000000000
    account_disabled:
      summary: account_disabled
      value:
        code: account_disabled
        http_status_code: 403
        message: >-
          The credentials provided with this request are invalid. Account has
          been disabled.
        parameters: {}
        unique_id: 00000000-0000-0000-0000-000000000000
    account_locked:
      summary: account_locked
      value:
        code: account_locked
        http_status_code: 403
        message: >-
          The credentials provided with this request are invalid. Account has
          been locked.
        parameters: {}
        unique_id: 00000000-0000-0000-0000-000000000000
    authorization_code_missing_code:
      summary: authorization_code_missing_code
      value:
        code: authorization_code_missing_code
        http_status_code: 403
        message: Authorization Code Flow required code parameter is missing
        parameters: {}
        unique_id: 00000000-0000-0000-0000-000000000000
    authorization_code_missing_csrf_token:
      summary: authorization_code_missing_csrf_token
      value:
        code: authorization_code_missing_csrf_token
        http_status_code: 403
        message: Authorization Code Flow required csrf token header is missing
        parameters: {}
        unique_id: 00000000-0000-0000-0000-000000000000
    authorization_code_missing_nonce:
      summary: authorization_code_missing_nonce
      value:
        code: authorization_code_missing_nonce
        http_status_code: 403
        message: Authorization Code Flow required nonce header is missing
        parameters: {}
        unique_id: 00000000-0000-0000-0000-000000000000
    authorization_code_missing_state:
      summary: authorization_code_missing_state
      value:
        code: authorization_code_missing_state
        http_status_code: 403
        message: Authorization Code Flow required state parameter is missing
        parameters: {}
        unique_id: 00000000-0000-0000-0000-000000000000
    authorization_code_response_invalid:
      summary: authorization_code_response_invalid
      value:
        code: authorization_code_response_invalid
        http_status_code: 403
        message: Authorization Code Response is invalid or expired.
        parameters: {}
        unique_id: 00000000-0000-0000-0000-000000000000
    expired_credentials:
      summary: expired_credentials
      value:
        code: expired_credentials
        http_status_code: 403
        message: The credentials provided with this request are expired.
        parameters: {}
        unique_id: 00000000-0000-0000-0000-000000000000
    invalid_credentials:
      summary: invalid_credentials
      value:
        code: invalid_credentials
        http_status_code: 403
        message: The credentials provided with this request are invalid.
        parameters: {}
        unique_id: 00000000-0000-0000-0000-000000000000
    missing_access_token:
      summary: missing_access_token
      value:
        code: missing_access_token
        http_status_code: 403
        message: No access_token was provided with this request.
        parameters: {}
        unique_id: 00000000-0000-0000-0000-000000000000
    missing_credentials:
      summary: missing_credentials
      value:
        code: missing_credentials
        http_status_code: 403
        message: No credentials provided with this request.
        parameters: {}
        unique_id: 00000000-0000-0000-0000-000000000000
    unsupported_media_type:
      summary: unsupported_media_type
      value:
        code: unsupported_media_type
        http_status_code: 415
        message: Request had an unsupported or no media type
        parameters: {}
        unique_id: 00000000-0000-0000-0000-000000000000
    too_many_requests:
      summary: too_many_requests
      value:
        code: too_many_requests
        http_status_code: 429
        message: >-
          The server is unable to process your request at the moment, please
          retry later.
        parameters: {}
        unique_id: 00000000-0000-0000-0000-000000000000
  securitySchemes:
    HEADER:
      in: header
      name: Authorization
      type: apiKey
      x-bearer-format: bearer
    QUERY:
      in: query
      name: access_token
      type: apiKey
    COOKIE:
      in: cookie
      name: extole_token
      type: apiKey

````