AppOmni Authorization Tokens API

The Authorization Tokens API from AppOmni — 7 operation(s) for authorization tokens.

Operations 7

POST /oauth/token/ Exchange refresh token for new access token #
POST /api/v1/core/oauthaccesstoken/manual/ Manually Grant Access Token with Specific Expiration Date #
GET /oauth/introspect/ Introspect Access Token #
POST /oauth/revoke/ Revoke Refresh Token #
DELETE /api/v1/core/oauthrefreshtoken/{token_id}/ Revoke Refresh Token by Token ID #
GET /api/v1/core/oauthapplication/ Get API Application by Client ID #
POST /api/v1/core/oauthapplication/{app_id}/rotate_client_secret/ Rotate an API Application's Client Secret #

Documentation

Specifications

Schemas & Data

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/appomni-authorization-tokens-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

appomni-authorization-tokens-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: AppOmni Identity and Access Authorization Tokens API
  description: 'Unified identities, AppOmni platform users, groups, roles and API authorization tokens.


    Derived faithfully from the AppOmni public Postman collection published by AppOmni at https://api.appomni.com/ — every path, method, parameter, request body and example response below is taken verbatim from that collection. No operation was invented.'
  version: 1.0.0
  contact:
    name: AppOmni
    url: https://appomni.com/support/
  license:
    name: Proprietary
    url: https://appomni.com/terms-of-service/
  x-generated-from: AppOmni public Postman collection (publishedId 2sBXc7Mjib, published 2026-02-04)
  x-generated-source: https://api.appomni.com/api/collections/45135595/2sBXc7Mjib?segregateAuth=true&versionTag=latest
  x-generated-method: derived
  x-generated-date: '2026-09-04'
servers:
- url: https://{instance}.appomni.com
  description: AppOmni tenant. Replace {instance} with your AppOmni subdomain — e.g. `acme` if you log in at acme.appomni.com.
  variables:
    instance:
      default: example
      description: Your AppOmni tenant subdomain
security:
- bearerAuth: []
tags:
- name: Authorization Tokens
paths:
  /oauth/token/:
    post:
      operationId: exchangeRefreshTokenForNewAccessToken
      summary: Exchange refresh token for new access token
      tags:
      - Authorization Tokens
      description: 'This is a standard OAuth 2.0 "Refresh Token Grant" flow that enables the exchange of a valid Refresh Token for a new Access Token. The valid Access Token can then be used to make authenticated API requests in the context of the user who granted the Refresh Token.


        Request Body


        Field

        Data Type

        Required

        Description

        Example


        grant_type

        String

        Yes

        OAuth2 grant type (must be "refresh_token")

        refresh_token


        refresh_token

        String

        Yes

        Your Refresh Token

        {{refreshtoken}}


        client_id

        String

        Yes

        The Client ID of your AppOmni API Application

        {{api_app_client_id}}


        client_secret

        String

        Yes

        The Client Secret of your AppOmni API Application

        {{api_app_client_secret}}


        Response Fields


        Field

        Data Type

        Description

        Example


        access_token

        String

        API access token

        XXXXX


        expires_in

        Integer

        Token expiration time in seconds

        3600


        token_type

        String

        Type of authentication token

        Bearer


        scope

        String

        Permissions granted to the token


        refresh_token

        String

        Token to refresh access token

        XXXXX'
      responses:
        '200':
          description: Exchange Refresh Token for New Access Token
          content:
            application/json:
              schema:
                type: object
              examples:
                ExchangeRefreshTokenforNewAccessToken:
                  summary: Exchange Refresh Token for New Access Token
                  value:
                    access_token: XXXXX
                    expires_in: 3600
                    token_type: Bearer
                    scope: ''
                    refresh_token: XXXXX
        '401':
          description: Unauthorized — missing or invalid AppOmni API token
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Forbidden — the token lacks permission for this resource
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
  /api/v1/core/oauthaccesstoken/manual/:
    post:
      operationId: manuallyGrantAccessTokenWithSpecificExpirationDate
      summary: Manually Grant Access Token with Specific Expiration Date
      tags:
      - Authorization Tokens
      description: 'Use this route to grant an Access Token with a custom expiration date. This can be used to create long-lived API tokens where necessary for service-to-service integrations that cannot execute the OAuth 2.0 token grant flow using a Refresh Token.


        When using this capability, a new Refresh Token will be created for the specified Application. An Access Token with the specified expiration date will be granted under that Refresh Token.


        In the request, application is the ID of the AppOmni API Application to grant the token under. The API token you are using to make this request must have access to the application.


        You can execute a GET request on /api/v1/core/oauthapplication/?limit=25&offset=0&ordering=-name to obtain ID''s for available API applications.


        Request Body


        Field

        Data Type

        Required

        Description

        Example


        application

        Integer

        Yes

        Application

        11472


        description

        String

        Yes

        Description of the resource

        Example Description. Setting to expire on 05/31...


        access_token_expiration

        String (ISO datetime)

        Yes

        Access token expiration

        2025-05-31T07:00:00.000Z


        Response Fields


        Field

        Data Type

        Description

        Example


        application

        Integer

        Application

        11472


        access_token_expiration

        String (ISO datetime)

        Access token expiration

        2025-05-31T07:00:00Z


        access_token

        String

        API access token

        XXXXX


        refresh_token

        String

        Token to refresh access token

        XXXXX


        description

        String

        Description of the resource

        Example Description. Setting to expire on 05/31...'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
            example:
              application: 11472
              description: Example Description. Setting to expire on 05/31/2025
              access_token_expiration: '2025-05-31T07:00:00.000Z'
      responses:
        '200':
          description: Example of manual token grant
          content:
            application/json:
              schema:
                type: object
              examples:
                Exampleofmanualtokengrant:
                  summary: Example of manual token grant
                  value:
                    application: 11472
                    access_token_expiration: '2025-05-31T07:00:00Z'
                    access_token: XXXXX
                    refresh_token: XXXXX
                    description: Example Description. Setting to expire on 05/31/2025
        '401':
          description: Unauthorized — missing or invalid AppOmni API token
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Forbidden — the token lacks permission for this resource
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
  /oauth/introspect/:
    get:
      operationId: introspectAccessToken
      summary: Introspect Access Token
      tags:
      - Authorization Tokens
      description: 'This is a RFC 7662-compliant Access Token Introspection endpoint. When making a query to the introspection endpoint with your valid access token in the Authorization header, you will get a response including the Client ID of the API Application the Access Token belongs to, the unix timestamp the token expires at, and the username of the user to which the token grants access under.


        https://datatracker.ietf.org/doc/html/rfc7662#section-2.2'
      responses:
        '200':
          description: Introspect Access Token
          content:
            text/plain:
              schema:
                type: string
              example: "{\n    \"active\": true,\n    \"exp\": 1788793177,\n    \"client_id\": \"XXX\",\n    \"username\": user123\"\n}"
        '401':
          description: Unauthorized — missing or invalid AppOmni API token
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Forbidden — the token lacks permission for this resource
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
  /oauth/revoke/:
    post:
      operationId: revokeRefreshToken
      summary: Revoke Refresh Token
      tags:
      - Authorization Tokens
      description: 'This is a RFC 7009-compliant revocation route for OAuth Refresh Tokens granted under AppOmni API Applications.


        This route should be called via POST with the token parameter containing the value of the Refresh Token to be revoked. The token, and all Access Tokens granted under it, will be immediately revoked.


        https://datatracker.ietf.org/doc/html/rfc7009#section-2.1'
      responses:
        '200':
          description: Successful response
        '401':
          description: Unauthorized — missing or invalid AppOmni API token
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Forbidden — the token lacks permission for this resource
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
  /api/v1/core/oauthrefreshtoken/{token_id}/:
    delete:
      operationId: revokeRefreshTokenByTokenID
      summary: Revoke Refresh Token by Token ID
      tags:
      - Authorization Tokens
      parameters:
      - name: token_id
        in: path
        required: true
        description: Path parameter token_id
        schema:
          type: string
      responses:
        '200':
          description: Successful response
        '401':
          description: Unauthorized — missing or invalid AppOmni API token
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Forbidden — the token lacks permission for this resource
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
  /api/v1/core/oauthapplication/:
    get:
      operationId: getAPIApplicationByClientID
      summary: Get API Application by Client ID
      tags:
      - Authorization Tokens
      description: Using this route you are able to query for an AppOmni API Application (OAuthApplication object) by Client ID. This will allow you to convert a Client ID to the API Application ID, which may be necessary for other operations (e.g. rotating the client secret via API).
      parameters:
      - name: client_id
        in: query
        required: false
        description: Query parameter client_id
        schema:
          type: string
        example: CLIENT_ID
      responses:
        '200':
          description: Get API Application by Client ID
          content:
            text/plain:
              schema:
                type: string
              example: "[\n    {\n        \"id\": 1,\n        \"created\": \"2025-09-07T14:59:37.872737Z\",\n        \"modified\": \"2025-09-07T14:59:37.872717Z\",\n        \"external_id\": null,\n        \"created_by\": 1,\n        \"modified_by\": null,\n        \"owner\": 1,\n        \"name\": \"Sample Application\",\n        \"description\": null\n        \"client_id\": \"ABCDEF123456\",\n        \"redirect_uris\": \"\",\n        \"client_type\": \"confidential\",\n        \"authorization_grant_type\": \"authorization-code\",\n        \"skip_authorization\": false,\n        \"allowed_scopes\": [],\n    }\n]"
        '401':
          description: Unauthorized — missing or invalid AppOmni API token
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Forbidden — the token lacks permission for this resource
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
  /api/v1/core/oauthapplication/{app_id}/rotate_client_secret/:
    post:
      operationId: rotateAnAPIApplicationSClientSecret
      summary: Rotate an API Application's Client Secret
      tags:
      - Authorization Tokens
      description: 'Making a POST request to this route with valid authorization credentials (must be a valid API token with access to manage the API Application in question) will immediately rotate the API Application''s client secret. The new client secret will be required for all future Access Token grant requests in conjunction with a valid Refresh Token.


        All existing Refresh Tokens will remain valid, and all Access Tokens previously granted and still valid will remain so until their expiration time.


        In most cases this action is only required if you believe your API Application''s Client Secret has been compromised. Otherwise, it is recommended you revoke and issue new Refresh Tokens.


        Response Fields


        Field

        Data Type

        Description

        Example


        client_secret

        String

        Client secret

        NEW_CLIENT_SECRET'
      parameters:
      - name: app_id
        in: path
        required: true
        description: Path parameter app_id
        schema:
          type: string
      responses:
        '200':
          description: Rotate an API Application's Client Secret
          content:
            application/json:
              schema:
                type: object
              examples:
                RotateanAPIApplicationsClientSecret:
                  summary: Rotate an API Application's Client Secret
                  value:
                    client_secret: NEW_CLIENT_SECRET
        '401':
          description: Unauthorized — missing or invalid AppOmni API token
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Forbidden — the token lacks permission for this resource
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    Error:
      type: object
      title: Error
      description: Standard Django REST Framework error envelope returned by the AppOmni API.
      properties:
        detail:
          type: string
          description: Human readable error message
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: 'AppOmni API access token, created and managed in the AppOmni platform under Settings > API Settings. Sent as `Authorization: Bearer <token>`.'