> ## Documentation Index
> Fetch the complete documentation index at: https://docs.capitalcheckin.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Exchange code for token

> Exchange an authorization code for an access token



## OpenAPI

````yaml post /oauth/token
openapi: 3.1.0
info:
  title: Capital Check In API
  description: >-
    API for the Capital Check In platform - Employee check-in management system
    with identity verification, geolocation, and schedule management
  license:
    name: MIT
  version: 1.0.0
  contact:
    name: Capital Check In Support
    email: hi@capitalcheckin.app
    url: https://capitalcheckin.app
servers:
  - url: https://api.capitalcheckin.app
    description: Production
security:
  - bearerAuth: []
paths:
  /oauth/token:
    post:
      tags:
        - OAuth2
      summary: Exchange code for token
      description: Exchange an authorization code for an access token
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/OAuthTokenRequest'
      responses:
        '200':
          description: Access token
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthTokenResponse'
        '400':
          description: Invalid code
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    OAuthTokenRequest:
      type: object
      required:
        - grant_type
        - client_id
        - client_secret
        - code
        - redirect_uri
      properties:
        grant_type:
          type: string
          enum:
            - authorization_code
            - refresh_token
          description: Tipo de grant
        client_id:
          type: string
          description: OAuth2 client ID
        client_secret:
          type: string
          description: OAuth2 client secret
        code:
          type: string
          description: Authorization code (for authorization_code)
        redirect_uri:
          type: string
          format: uri
          description: Redirect URI
        refresh_token:
          type: string
          description: Refresh token (para refresh_token)
    OAuthTokenResponse:
      type: object
      properties:
        access_token:
          type: string
          description: Access token
        token_type:
          type: string
          enum:
            - bearer
          description: Token type
        expires_in:
          type: integer
          description: Expiration time in seconds
        refresh_token:
          type: string
          description: Refresh token
        scope:
          type: string
          description: Granted permissions
    Error:
      type: object
      required:
        - error
        - message
      properties:
        error:
          type: string
          description: Error code
        message:
          type: string
          description: Descriptive error message
        details:
          type: object
          description: Additional error details
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: OAuth2
      description: OAuth2 access token for authentication

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.