> ## Documentation Index
> Fetch the complete documentation index at: https://docs-staging-quickstart-revamp.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

> Learn how to request Access Tokens using the Authorize endpoint when authenticating users and include the target audience and scope of access requested by the app and granted by the user.

# Get Access Tokens

To access your API, you must request an [access token](/docs/secure/tokens/access-tokens) when authenticating a user.

<Callout icon="file-lines" color="#0EA5E9" iconType="regular">
  These Auth0 tools help you modify your application to authenticate users:

  * [Quickstarts](/docs/quickstarts) are the easiest way to implement authentication. They show you how to use [Universal Login](/docs/authenticate/login/auth0-universal-login/universal-login-vs-classic-login) and Auth0's language- and framework-specific SDKs.
  * The [Auth0 Authentication API](https://auth0.com/docs/api/authentication) is a reference for those who prefer to write code independently. First, identify [which flow to use](/docs/get-started/authentication-and-authorization-flow/which-oauth-2-0-flow-should-i-use). Then follow the instructions to implement that flow.
</Callout>

To request an <Tooltip tip="Access Token: Authorization credential, in the form of an opaque string or JWT, used to access an API." cta="View Glossary" href="/docs/glossary?term=access+token">access token</Tooltip>, make a POST call to the [token URL](https://auth0.com/docs/api/authentication#client-credentials-flow).

#### Example POST to token URL

<CodeGroup>
  ```bash cURL lines
  curl --request POST \
    --url 'https://{yourDomain}/oauth/token' \
    --header 'content-type: application/x-www-form-urlencoded' \
    --data grant_type=client_credentials \
    --data client_id=YOUR_CLIENT_ID \
    --data client_secret=YOUR_CLIENT_SECRET \
    --data audience=YOUR_API_IDENTIFIER
  ```

  ```csharp C# lines
  var client = new RestClient("https://{yourDomain}/oauth/token");
  var request = new RestRequest(Method.POST);
  request.AddHeader("content-type", "application/x-www-form-urlencoded");
  request.AddParameter("application/x-www-form-urlencoded", "grant_type=client_credentials&client_id=YOUR_CLIENT_ID&client_secret=YOUR_CLIENT_SECRET&audience=YOUR_API_IDENTIFIER", ParameterType.RequestBody);
  IRestResponse response = client.Execute(request);
  ```

  ```go Go lines expandable
  package main

  import (
  	"fmt"
  	"strings"
  	"net/http"
  	"io/ioutil"
  )

  func main() {

  	url := "https://{yourDomain}/oauth/token"

  	payload := strings.NewReader("grant_type=client_credentials&client_id=YOUR_CLIENT_ID&client_secret=YOUR_CLIENT_SECRET&audience=YOUR_API_IDENTIFIER")

  	req, _ := http.NewRequest("POST", url, payload)

  	req.Header.Add("content-type", "application/x-www-form-urlencoded")

  	res, _ := http.DefaultClient.Do(req)

  	defer res.Body.Close()
  	body, _ := ioutil.ReadAll(res.Body)

  	fmt.Println(res)
  	fmt.Println(string(body))

  }
  ```

  ```java Java lines
  HttpResponse<String> response = Unirest.post("https://{yourDomain}/oauth/token")
    .header("content-type", "application/x-www-form-urlencoded")
    .body("grant_type=client_credentials&client_id=YOUR_CLIENT_ID&client_secret=YOUR_CLIENT_SECRET&audience=YOUR_API_IDENTIFIER")
    .asString();
  ```

  ```javascript Node.JS lines
  var axios = require("axios").default;

  var options = {
    method: 'POST',
    url: 'https://{yourDomain}/oauth/token',
    headers: {'content-type': 'application/x-www-form-urlencoded'},
    data: new URLSearchParams({
      grant_type: 'client_credentials',
      client_id: 'YOUR_CLIENT_ID',
      client_secret: 'YOUR_CLIENT_SECRET',
      audience: 'YOUR_API_IDENTIFIER'
    })
  };

  axios.request(options).then(function (response) {
    console.log(response.data);
  }).catch(function (error) {
    console.error(error);
  });
  ```

  ```obj-c Obj-C lines expandable
  #import <Foundation/Foundation.h>

  NSDictionary *headers = @{ @"content-type": @"application/x-www-form-urlencoded" };

  NSMutableData *postData = [[NSMutableData alloc] initWithData:[@"grant_type=client_credentials" dataUsingEncoding:NSUTF8StringEncoding]];
  [postData appendData:[@"&client_id=YOUR_CLIENT_ID" dataUsingEncoding:NSUTF8StringEncoding]];
  [postData appendData:[@"&client_secret=YOUR_CLIENT_SECRET" dataUsingEncoding:NSUTF8StringEncoding]];
  [postData appendData:[@"&audience=YOUR_API_IDENTIFIER" dataUsingEncoding:NSUTF8StringEncoding]];

  NSMutableURLRequest *request = [NSMutableURLRequest requestWithURL:[NSURL URLWithString:@"https://{yourDomain}/oauth/token"]
                                                         cachePolicy:NSURLRequestUseProtocolCachePolicy
                                                     timeoutInterval:10.0];
  [request setHTTPMethod:@"POST"];
  [request setAllHTTPHeaderFields:headers];
  [request setHTTPBody:postData];

  NSURLSession *session = [NSURLSession sharedSession];
  NSURLSessionDataTask *dataTask = [session dataTaskWithRequest:request
                                              completionHandler:^(NSData *data, NSURLResponse *response, NSError *error) {
                                                  if (error) {
                                                      NSLog(@"%@", error);
                                                  } else {
                                                      NSHTTPURLResponse *httpResponse = (NSHTTPURLResponse *) response;
                                                      NSLog(@"%@", httpResponse);
                                                  }
                                              }];
  [dataTask resume];
  ```

  ```php PHP lines expandable
  $curl = curl_init();

  curl_setopt_array($curl, [
    CURLOPT_URL => "https://{yourDomain}/oauth/token",
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_ENCODING => "",
    CURLOPT_MAXREDIRS => 10,
    CURLOPT_TIMEOUT => 30,
    CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
    CURLOPT_CUSTOMREQUEST => "POST",
    CURLOPT_POSTFIELDS => "grant_type=client_credentials&client_id=YOUR_CLIENT_ID&client_secret=YOUR_CLIENT_SECRET&audience=YOUR_API_IDENTIFIER",
    CURLOPT_HTTPHEADER => [
      "content-type: application/x-www-form-urlencoded"
    ],
  ]);

  $response = curl_exec($curl);
  $err = curl_error($curl);

  curl_close($curl);

  if ($err) {
    echo "cURL Error #:" . $err;
  } else {
    echo $response;
  }
  ```

  ```python Python lines
  import http.client

  conn = http.client.HTTPSConnection("")

  payload = "grant_type=client_credentials&client_id=YOUR_CLIENT_ID&client_secret=YOUR_CLIENT_SECRET&audience=YOUR_API_IDENTIFIER"

  headers = { 'content-type': "application/x-www-form-urlencoded" }

  conn.request("POST", "/{yourDomain}/oauth/token", payload, headers)

  res = conn.getresponse()
  data = res.read()

  print(data.decode("utf-8"))
  ```

  ```ruby Ruby lines
  require 'uri'
  require 'net/http'
  require 'openssl'

  url = URI("https://{yourDomain}/oauth/token")

  http = Net::HTTP.new(url.host, url.port)
  http.use_ssl = true
  http.verify_mode = OpenSSL::SSL::VERIFY_NONE

  request = Net::HTTP::Post.new(url)
  request["content-type"] = 'application/x-www-form-urlencoded'
  request.body = "grant_type=client_credentials&client_id=YOUR_CLIENT_ID&client_secret=YOUR_CLIENT_SECRET&audience=YOUR_API_IDENTIFIER"

  response = http.request(request)
  puts response.read_body
  ```

  ```swift Swift lines expandable
  import Foundation

  let headers = ["content-type": "application/x-www-form-urlencoded"]

  let postData = NSMutableData(data: "grant_type=client_credentials".data(using: String.Encoding.utf8)!)
  postData.append("&client_id=YOUR_CLIENT_ID".data(using: String.Encoding.utf8)!)
  postData.append("&client_secret=YOUR_CLIENT_SECRET".data(using: String.Encoding.utf8)!)
  postData.append("&audience=YOUR_API_IDENTIFIER".data(using: String.Encoding.utf8)!)

  let request = NSMutableURLRequest(url: NSURL(string: "https://{yourDomain}/oauth/token")! as URL,
                                          cachePolicy: .useProtocolCachePolicy,
                                      timeoutInterval: 10.0)
  request.httpMethod = "POST"
  request.allHTTPHeaderFields = headers
  request.httpBody = postData as Data

  let session = URLSession.shared
  let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
    if (error != nil) {
      print(error)
    } else {
      let httpResponse = response as? HTTPURLResponse
      print(httpResponse)
    }
  })

  dataTask.resume()
  ```
</CodeGroup>

##### Parameters

<table class="table">
  <thead>
    <tr>
      <th>Parameter Name</th>
      <th>Description</th>
    </tr>
  </thead>

  <tbody>
    <tr>
      <td><code>grant\_type</code></td>
      <td>Set this to "client\_credentials".</td>
    </tr>

    <tr>
      <td><code>client\_id</code></td>
      <td>Your application's Client ID. You can find this value on the <a href="https://manage.auth0.com/#/applications">application's settings tab</a>.</td>
    </tr>

    <tr>
      <td><code>client\_secret</code></td>
      <td>Your application's Client Secret. You can find this value on the <a href="https://manage.auth0.com/#/applications">application's settings tab</a>.  To learn more about available application authentication methods, read <a href="/docs/secure/application-credentials">Application Credentials</a>.</td>
    </tr>

    <tr>
      <td><code>audience</code></td>
      <td>The audience for the token, which is your API. You can find this in the <strong>Identifier</strong> field on your <a href="https://manage.auth0.com/#/apis">API's settings tab</a>.</td>
    </tr>

    <tr>
      <td><code>organization</code></td>
      <td>Optional. The organization name or identifier you want the request to be associated with. To learn more, read <a href="/docs/manage-users/organizations/organizations-for-m2m-applications">Machine-to-Machine Access for Organizations</a>.</td>
    </tr>
  </tbody>
</table>

#### Response

You receive an `HTTP 200` response with a payload containing `access_token`, `token_type`, and `expires_in` values:

```json lines
{
  "access_token":"eyJz93a...k4laUWw",
  "token_type":"Bearer",
  "expires_in":86400
}
```

<Warning>
  Validate your tokens before saving them. To learn how, read [Validate ID Tokens](/docs/secure/tokens/id-tokens/validate-id-tokens) and [Validate Access Tokens](/docs/secure/tokens/access-tokens/validate-access-tokens).
</Warning>

## Control access token audience

When a user authenticates, you request an access token and include the target <Tooltip tip="Audience: Unique identifier of the audience for an issued token. Named aud in a token, its value contains the ID of either an application (Client ID) for an ID Token or an API (API Identifier) for an Access Token." cta="View Glossary" href="/docs/glossary?term=audience">audience</Tooltip> and scope of access in your request. The application uses the `/authorize` endpoint to request access. This access is both requested by the application and granted by the user during authentication

You can configure your tenant to always include a default audience.

<table class="table">
  <thead>
    <tr>
      <th>Token Use</th>
      <th>Format</th>
      <th>Requested Audience</th>
      <th>Requested Scope</th>
    </tr>
  </thead>

  <tbody>
    <tr>
      <td>/userinfo endpoint</td>
      <td>Opaque</td>
      <td>tenant name (<code>\{yourDomain}</code>), no value for <code>audience</code> parameter, no <code>audience</code> parameter passed</td>
      <td><code>openid</code></td>
    </tr>

    <tr>
      <td>Auth0 Management API</td>
      <td>JWT</td>
      <td>Management API v2 identifier (`https://{tenant}.auth0.com/api/v2/`)</td>

      <td />
    </tr>

    <tr>
      <td>Your own custom API</td>
      <td>JWT</td>
      <td>The API Identifier for your custom API registered in the Auth0 Dashboard</td>

      <td />
    </tr>
  </tbody>
</table>

In only one specific instance, access tokens can have multiple target audiences. This requires that your custom API's <Tooltip tip="Signing Algorithm: Algorithm used to digitally sign tokens to ensure the token has not been tampered with." cta="View Glossary" href="/docs/glossary?term=signing+algorithm">signing algorithm</Tooltip> is set to **RS256**. To learn more, read [Token Best Practices](/docs/secure/tokens/token-best-practices).

### Multiple audiences

If you specify an audience of your custom API identifier and a scope of `openid`, then the resulting access token's `aud` claim will be an array rather than a string, and the access token will be valid for both your custom API and for the `/userinfo` endpoint. Your access tokens can only have two or more audiences if you use a single custom API as well as Auth0's `/userinfo` endpoint.

### Custom domains and the Auth0 Management API

Auth0 issues tokens with an issuer (`iss)` claim of whichever domain you used when requesting the token. [Custom domain](/docs/customize/custom-domains) users can use either their <Tooltip tip="Custom Domain: Third-party domain with a specialized, or vanity, name." cta="View Glossary" href="/docs/glossary?term=custom+domain">custom domain</Tooltip> or their Auth0 domain.

For example, suppose you have a custom domain, `https://login.northwind.com`. If you request an access token from `https://login.northwind.com/authorize`, your token's `iss` claim will be `https://login.northwind.com/`. However, if you request an access token from `https://northwind.auth0.com/authorize`, your token's `iss` claim will be `https://northwind.auth0.com/`.

If you request an access token from your custom domain with the target audience of the Auth0 <Tooltip tip="Management API: A product to allow customers to perform administrative tasks." cta="View Glossary" href="/docs/glossary?term=Management+API">Management API</Tooltip>, then you **must** call the Auth0 Management API from your custom domain. Otherwise your access token is considered invalid.

## Renew access tokens

By default, an access token for a custom API is valid for 86400 seconds (24 hours). You can [shorten the time period before the token expires](/docs/secure/tokens/access-tokens/update-access-token-lifetime).

After an access token has expired, you can renew your access token. To do so either re-authenticate the user using Auth0 or use a [refresh token](/docs/secure/tokens/refresh-tokens).

## Learn more

* [Validate Access Tokens](/docs/secure/tokens/access-tokens/validate-access-tokens)
* [Use Access Tokens](/docs/secure/tokens/access-tokens/use-access-tokens)
* [JSON Web Tokens](/docs/secure/tokens/json-web-tokens)
* [Refresh Tokens](/docs/secure/tokens/refresh-tokens)
* [Identity Provider Access Tokens](/docs/secure/tokens/access-tokens/identity-provider-access-tokens)
* [Management API Access Tokens](/docs/secure/tokens/access-tokens/management-api-access-tokens)
