Get Access-Token
POST https://apps.fortnox.se/oauth-v1/tokenCredentials is the Base64 encoding of ClientId and Client-Secret, separated with a colon.
Content-type: application/x-www-form-urlencoded
Authorization: Basic {Credentials}Body example
The body shall be sent by using the "application/x-www-form-urlencoded" format, with a character encoding of UTF-8.
grant_type (required) - Value MUST be set to "authorization_code".
code (required) - The authorization code received from the authorization request.
redirect_uri (required) - If the "redirect_uri" parameter was included in the authorization request, and their values MUST be identical.
code_verifier (optional, required if a code_challenge was sent in the authorization request) - The original code_verifier generated by the client before deriving the code_challenge. The authorization server will hash this value using the method specified in code_challenge_method and compare it against the code_challenge received in the authorization request. If they do not match, the token request will be rejected.
Note that this requirement is tied to whether a code_challenge was actually included in the authorization request — not to whether PKCE is toggled as required in the Developer Portal. If the app owner has chosen to use PKCE voluntarily (i.e. the toggle is off but a code_challenge was still sent), code_verifier is still required in the token request. Conversely, if no code_challenge was sent in the authorization request, code_verifier should not be included here.
grant_type=authorization_code&code={Authorization-Code}&redirect_uri=https://mysite.org/activation&code_verifier={Code-Verifier}{
"access_token": "xyz...",
"refresh_token": "a7302e6b-b1cb-4508-b884-cf9abd9a51de",
"scope": "companyinformation",
"expires_in": 3600,
"token_type": "bearer"
}:format(webp))
:format(webp))
:format(webp))