Skip to content

Signin  >  Structures  >  CreateOAuth2TokenResponseBody

CreateOAuth2TokenResponseBody

Structure Class

CreateOAuth2TokenResponseBody dataclass

Response body payload for CreateOAuth2Token operation The response content depends on the grant_type from the request: - grant_type=authorization_code: Returns all fields including refresh_token and id_token - grant_type=refresh_token: Returns access_token, token_type, expires_in, refresh_token (no id_token)

Attributes

access_token class-attribute instance-attribute
access_token: AccessToken = field(repr=False)

Scoped-down AWS credentials (15 minute duration) Present for both authorization code redemption and token refresh

expires_in instance-attribute
expires_in: int

Time to expiry in seconds (maximum 900) Present for both authorization code redemption and token refresh

id_token class-attribute instance-attribute
id_token: str | None = None

ID token containing user identity information Present only in authorization code redemption response (grant_type=authorization_code) Not included in token refresh responses

refresh_token class-attribute instance-attribute
refresh_token: str = field(repr=False)

Encrypted refresh token with cnf.jkt (SHA-256 thumbprint of presented jwk) Always present in responses (required for both flows)

token_type instance-attribute
token_type: str

Token type indicating this is AWS SigV4 credentials Value is "aws_sigv4" for both flows