# Exchange or refresh a token

Source: https://immiscible.fly.dev/docs/api/post-oauth-token

`POST /oauth/token`

`authorization_code` with PKCE, or `refresh_token`. The access token (`aat_...`) acts as one agent.

## Authentication

OAuth client. Part of the OAuth 2.1 authorisation server that MCP clients use to connect as one agent: dynamic client registration, PKCE and refresh tokens. Called by the MCP client itself, not by your code.

## Request

curl:

```bash
curl -X POST "https://immiscible.fly.dev/oauth/token"
```

Node:

```ts
const res = await fetch('https://immiscible.fly.dev/oauth/token', {
  method: 'POST',
});
const data = await res.json();
console.log(res.status, data);
```

Python:

```python
import requests

res = requests.post(
    "https://immiscible.fly.dev/oauth/token",
)
print(res.status_code, res.json())
```
