# Token

Exchange a signed assertion for a bearer token, without sending a password.
Sign a short-lived JWT assertion with the private key whose public half you
registered with Jiko, and post it here. You receive the same bearer token
`/api/v1/login/` returns, and use it the same way.
This is an OAuth token endpoint (RFC 6749, RFC 7523): post
`application/x-www-form-urlencoded` with `grant_type` set to
`urn:ietf:params:oauth:grant-type:jwt-bearer` and `assertion` set to the signed
JWT. The response carries `access_token`, `token_type` (always `Bearer`), and
`expires_in` in seconds.
Failures return `400` with the RFC 6749 §5.2 body — `{"error", "error_description"}`
— rather than this API's usual error shape: `invalid_request` if `grant_type` or
`assertion` is missing, `unsupported_grant_type` for any other grant, and
`invalid_grant` if the assertion itself was rejected.
The assertion must be signed with `EdDSA` (Ed25519) or `ES256` (NIST P-256),
carry your key's `kid` in the header, and contain these claims:
| Claim | Value |
|  --- | --- |
| `iss` | your API username |
| `sub` | your API username (same as `iss`) |
| `aud` | the audience Jiko issued you with your key |
| `exp` | no more than 5 minutes ahead — 60 seconds is recommended |
| `iat` | the time you signed it |
| `jti` | a unique id; an assertion may be exchanged only once |

Request signing still applies to every other endpoint: this replaces your
password, not your shared secret.
See [Authentication](/products/partner-api/guides/building/auth).

Endpoint: POST /token/
Version: Version: ea915464

## Request fields (application/x-www-form-urlencoded):

  - `grant_type` (any)

  - `assertion` (any)

## Response 200:

  - `200` (unknown)
    Successful Response

## Response 200 fields (application/json):

  - `access_token` (string, required)

  - `token_type` (string)

  - `expires_in` (integer, required)

## Response 400:

  - `400` (unknown)
    Bad Request

## Response 400 fields (application/json):

  - `error` (string, required)

  - `error_description` (string, required)

## Response 401:

  - `401` (unknown)
    Unauthorized

## Response 422:

  - `422` (unknown)
    Validation Error

## Response 422 fields (application/json):

  - `detail` (array)

  - `detail.loc` (array, required)

  - `detail.msg` (string, required)

  - `detail.type` (string, required)

  - `detail.input` (any)

  - `detail.ctx` (object)

## Response 200 examples:

  - `0` (unknown)

