
Exchange the authorization code for an access token and a refresh token.
| Parameter | Description |
| client_id | required A unique ID displayed under Self Client > Client Secret. |
| client_secret | required A unique confidential secret displayed under Self Client > Client Secret. |
| grant_type | required Should be passed with the value authorization_code. |
| code | required The authorization code generated in the previous step. |
| Parameter | Description |
| access_token | An authorized key that can be used by your application to access the required resource (mentioned in the scope). Validity: 1 hour. |
| refresh_token | A special token that can be used by your application to refresh the access token once it is expired. This token won't expire. |
| api_domain | The domain the app needs to make service API requests to. |
| token_type | Indicates the type of access token that is generated. The token type that is used in Zoho's OAuth implementation is Bearer. |
| expires_in | Indicates the time (in seconds) in which the access token will expire. |
Make request calls to the service you want to access through the api_domain you get from the response of the access token request. Using an access token, you can access the resource for an hour, after which it will expire. To get a new access token, use the refresh token (see Step 4).
When an access token expires, get a new access token using the refresh token.
| Parameter | Description |
| client_id | required A unique ID displayed under Self Client > Client Secret. |
| client_secret | required A unique confidential secret displayed under Self Client > Client Secret. |
| grant_type | required Should be passed with the value refresh_token. |
| refresh_token | required The refresh token you've obtained in step 2. |
| Parameter | Description |
| access_token | An authorized key that can be used by your application to access the required resource (mentioned in the scope). Validity: 1 hour. |
| api_domain | The domain the app needs to make service API requests to. |
| token_type | Indicates the type of access token that is generated. The token type that is used in Zoho's OAuth implementation is Bearer. |
| expires_in | Indicates the time (in seconds) in which the access token will expire. |
Copied
Note: The accounts-server-url is specific to the location (i.e., datacenter) where the client is registered. See all the server-specific URLs
Copied
Copied
Copied
Note: The accounts-server-url is specific to the location (i.e., datacenter) where the client is registered. See all the server-specific URLs
Copied
Copied
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.