> For the complete documentation index, see [llms.txt](https://docs.fortifiedid.se/access/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.fortifiedid.se/access/key-components/modules/oidc/token-endpoint/authorization-code.md).

# Authorization code

Configuration and usage guidance for Authorization code in Fortified ID Access.

For the authorization code flow, calling the token endpoint is the second step of the flow. HTTP POST is used for the token endpoint.

```
Example: http://127.0.0.1:8080/oidc/tenant1/token-endpoint
```

#### Request parameters

These parameters must be posted as a part of the URL-encoded form values.

{% hint style="info" %}
**Note:** Mandatory request parameters can be configured on each OIDC provider. Mandatory values below are the default behaviour.
{% endhint %}

<table data-full-width="true"><thead><tr><th>Parameter</th><th>Description</th><th data-type="checkbox">Mandatory</th></tr></thead><tbody><tr><td><code>code</code></td><td>The value that was returned from the authorization endpoint.</td><td>true</td></tr><tr><td><code>client_id</code></td><td>Identifies the client and must match the value configured in FortifiedID Integrity.</td><td>false</td></tr><tr><td><code>client_secret</code></td><td>Authenticates the client and must match the value configured in FortifiedID Integrity.</td><td>false</td></tr><tr><td><code>grant_type</code></td><td>Supported value is <code>authorization_code</code>.</td><td>false</td></tr><tr><td><code>redirect_uri</code></td><td>Specifies the redirect location. It must match the value configured in FortifiedID Integrity.</td><td>true</td></tr><tr><td><code>code_verifier</code></td><td>Required if <code>code_challenge</code> was used in the authorization endpoint request.</td><td>false</td></tr></tbody></table>

The token endpoint accepts either:

* client authentication with `client_secret_basic` or `client_secret_post`
* PKCE with `code_verifier`

If `code_verifier` is present, `client_secret` is not required. If neither client authentication nor PKCE is used, the request is rejected.

When PKCE or `client_secret_post` is used, `client_id` must still be included so the relying party can be resolved.

#### Client authentication methods

{% hint style="info" %}
**Parameter:** `token_endpoint_auth_methods_supported`

in discovery\_meta configuration section.
{% endhint %}

FortifiedID Integrity supports the following methods:

{% tabs %}
{% tab title="Parameters" %}

| Method                | Description                                                                         |
| --------------------- | ----------------------------------------------------------------------------------- |
| `client_secret_basic` | Provide 'clientid' and 'client\_secret' in the Authorization header. (Basic auth)   |
| `client_secret_post`  | Provide 'clientid' and 'client\_secret' as parameters in the POST request body.     |
| `none`                | For PKCE use. Provide the 'code\_verifier' as a parameter in the POST request body. |
| {% endtab %}          |                                                                                     |

{% tab title="Example" %}

```json
"discovery_meta": {
    ...
    "token_endpoint_auth_methods_supported" : 
        ["client_secret_post", "client_secret_basic"]
    ...
}
```

{% endtab %}
{% endtabs %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.fortifiedid.se/access/key-components/modules/oidc/token-endpoint/authorization-code.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
