Mint a short-lived access token.
POST/access_token
Creates a pair of access credentials — a token and a secret — that a client may use in place of the consumer credentials, and that expires on its own.
The request must be authenticated with consumer credentials. An
existing access token cannot mint another one; presenting an access
token here fails with forbidden (code 6) Consumer credentials required to create access credentials.
The lifetime is controlled by ttl_seconds in the request body; see
CreateAccessTokenRequest for its default and clamping behaviour. The
expiry is not echoed back — the response carries only token and
secret, so record the lifetime you asked for if you need to know when
the token dies.
Request
Responses
- 200
- 401
- 403
- default
The new access credentials. Only token and secret are returned.
Credentials were missing or invalid. The response carries
WWW-Authenticate: Basic realm="Feed.fm".
Response Headers
The authentication challenge. Always Basic realm="Feed.fm".
Basic realm="Feed.fm"forbidden (code 6) — Consumer credentials required to create access credentials: the request was authenticated with an access
token rather than the consumer credentials.
Note that DELETE /access_token/{access_token} reports this same
condition differently, as a 404 missingObject. The two routes are
deliberately not symmetric here.
An error occurred.