Provides OAuth JWT endpoints for app login, token refresh and logout.

Request or refresh OAuth JWT tokens

Issues JWT access and refresh tokens for frontend/mobile app clients. Supports grant_type=password for username/password login and grant_type=refresh_token for refreshing an existing session without cookies.

Documentation

POST JSON /oauth/login
Requests
Description Example
Content-Type: application/x-www-form-urlencoded
grant_type=password&client_id=flutter-app&username=user@example.com&password=secret
grant_type=refresh_token&client_id=flutter-app&refresh_token=<refresh-token>
Responses
Description Example
200
Content-Type: application/json
{
  "access_token": "<jwt-access-token>",
  "token_type": "Bearer",
  "expires_in": 900,
  "refresh_token": "<jwt-refresh-token>"
}
400 The grant request is invalid.
Content-Type: application/json
{
  "error": "invalid_grant",
  "error_description": "Invalid refresh_token request"
}

Logout and revoke OAuth JWT tokens

Revokes the bearer access token used for the request. If a matching refresh_token is supplied in the form body, it is revoked as well. The endpoint does not use cookies.

Documentation

POST JSON /oauth/logout
Parameter
Name Description Example
Authorization
Required
Bearer access token to revoke.
Requests
Description Example
Content-Type: application/x-www-form-urlencoded
refresh_token=<refresh-token>
Responses
Description Example
200
Content-Type: application/json
{
  "success": true
}
401 The bearer token is missing, invalid or already revoked.
Content-Type: application/json
{
  "error": "invalid_token",
  "error_description": "Missing, invalid or revoked bearer token"
}