Skip to main content

IMS Platform Auth APIs

The IMS Platform Auth service is OAuth compliant and we do not recommend attempting your own OAuth API implementation. Instead, you use the available libraries for your chosen programming language. See more about this in the Recommended OAuth Libraries and Resources guide.

Authorization Endpoint

You should make authorization requests to retrieve the Authorization Code against:


The only supported OAuth Authorization Grant Types are Authorization Code and Authorization Code with PKCE extension. Read more about the difference between public and private OAuth Clients in the OAuth Clients guide.

Token Endpoint

You should make token requests to exchange an Authorization Code for an Access Token or to exchange a Refresh Token for an Access Token against:

To generate a Refresh Token alongside the Access Token you should specify generate_access_token=true in your exchange request.

Recommended libraries:

Useful resources: