0.x — pre-release, no compatibility promise yet.What this means
Exchange a code or a refresh token for tokens
Exchange an authorization code (with its PKCE verifier) or a refresh token for an access token and a new
refresh token. Errors are OAuth JSON (error, error_description). Too many failed exchanges from one app and
address: 429 with Retry-After.
Request Bodyrequired
Section titled “Request Bodyrequired”object
Authorization_code: the code from the redirect
Authorization_code: exactly the one in the authorization request
Authorization_code: the PKCE verifier (43-128 characters)
Refresh_token: the current refresh token (single use)
Refresh_token: optional, narrower scopes (space-separated)
Required for a public app; a confidential app may send it with client_secret instead of HTTP Basic
client_secret_post (or use HTTP Basic)
Responses
Section titled “ Responses ”Successful Response
Returned by oauth.token.
object
A Taskadence access token (tkd_live_…), 1 hour
Seconds
tkdr_… - single use: each refresh returns a new one
Space-separated scopes this access token holds
Example
{ "access_token": "tkd_live_Ab3xQ9eLr0v2Zk5n8WcHt1YpUo4MiGs7Fj6Da-_Bq0R", "expires_in": 3600, "refresh_token": "tkdr_Zk5n8WcHt1YpUo4MiGs7Fj6Da-_Bq0RAb3xQ9eLr0v2", "scope": "tasks:write projects:read", "token_type": "Bearer"}An OAuth error (invalid_request, invalid_grant, invalid_scope, unsupported_grant_type)
Client authentication failed (invalid_client)
Too many failed token requests from this app and address; wait Retry-After seconds
An RFC 9457 problem details object - the body of every error response. detail is the human-readable explanation; request_id identifies the request for support.
object
about:blank or a urn:taskadence:problem:* identifier
Human-readable explanation (a string; for a 422, the list of validation errors)
Structured failures: validation errors, or {loc, msg, allowed} for a bad parameter
object
On an mfa-required problem only: enrolled (does the person have an authenticator app set up), required_for (all or admins) and reason (org_policy: the organization’s requirement; step_up: this action needs a second step)
object
Example
{ "type": "about:blank", "title": "Forbidden", "status": 403, "detail": "This task is restricted to other users", "instance": "/v1/tasks/T123", "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11", "errors": [ {} ], "mfa": { "enrolled": false, "required_for": "all", "reason": "org_policy" }}