Avaya Access Token API

Includes token related operations.

Operations 2

POST /{accountId}/protocol/openid-connect/token Generates an access token #
POST /protocol/openid-connect/token Generate Access Token #

Documentation

Specifications

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/avaya-access-token-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

avaya-access-token-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Avaya Access Token API
  license:
    name: Avaya Software Development Kit (SDK) Software License Terms
    url: http://support.avaya.com/css/P8/documents/101038288
  version: '1.0'
  description: 'Operations tagged Access Token across 2 of this provider''s published API definitions: avaya-axp-auth-openapi-original.json, avaya-infinity-access-token-openapi-original.json. Each path carries the servers of the definition it was published in.'
servers:
- url: '{protocol}://{server}{basePath}'
  description: Open API
  variables:
    protocol:
      enum:
      - https
      default: https
    server:
      default: HOST-REGION.api.avayacloud.com
    basePath:
      default: /api/auth/v1
- url: https://core.{customer-subdomain}.ec.avayacloud.com/auth/realms/avaya
  description: Avaya Infinity Authentication
  variables:
    customer-subdomain:
      default: avaya1234
      description: Your Infinity instance subdomain (e.g., avaya1234, acme-corp-prod)
tags:
- name: Access Token
  description: Includes token related operations.
paths:
  /{accountId}/protocol/openid-connect/token:
    post:
      tags:
      - Access Token
      summary: Generates an access token
      description: 'Request to obtain a token.


        A&A supports three grant types. A&A requires the client to authenticate itself with every one of these grant types, even those that additionally authenticate a user.


        **The 3 options for grant_type include:**


        * client_credentials

        * password

        * refresh_token


        The request body for each grant type is defined below. In addition, each API invocation requires the appkey in the header.'
      operationId: postGenerateToken
      parameters:
      - $ref: '#/components/parameters/accountId'
      requestBody:
        description: 'Request payload

          '
        content:
          application/x-www-form-urlencoded:
            schema:
              oneOf:
              - $ref: '#/components/schemas/GenerateTokenRequest'
              - $ref: '#/components/schemas/ResourceOwnerPasswordRequest'
              - $ref: '#/components/schemas/RefreshTokenRequest'
      responses:
        '200':
          description: Returns token.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenerateTokenResponse'
        '400':
          description: Bad Request
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
              examples:
                default:
                  $ref: '#/components/examples/ErrorConstraintViolation'
        '401':
          description: Unauthorized.
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
              examples:
                default:
                  $ref: '#/components/examples/ErrorUnauthorized'
        '403':
          description: Forbidden.
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
              examples:
                default:
                  $ref: '#/components/examples/ErrorForbidden'
        '404':
          description: Not Found.
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
              examples:
                default:
                  $ref: '#/components/examples/ErrorNotFound'
        '409':
          description: Conflict.
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
              examples:
                default:
                  $ref: '#/components/examples/ErrorConflict'
        '415':
          description: Unsupported Media Type.
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
              examples:
                default:
                  $ref: '#/components/examples/ErrorUnsupportedMediaType'
        '500':
          description: Internal Server Error.
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
              examples:
                default:
                  $ref: '#/components/examples/ErrorInternalServerError'
      security:
      - {}
      - ApiKeyAuth: []
    servers:
    - url: '{protocol}://{server}{basePath}'
      description: Open API
      variables:
        protocol:
          enum:
          - https
          default: https
        server:
          default: HOST-REGION.api.avayacloud.com
        basePath:
          default: /api/auth/v1
  /protocol/openid-connect/token:
    post:
      tags:
      - Access Token
      summary: Generate Access Token
      description: 'Generate an OAuth 2.0 access token using the client credentials grant type.


        **Grant Type:** Only `client_credentials` is supported. This is a server-to-server

        authentication flow where your backend server exchanges credentials for an access token.


        **Token Format:** The access token is a JSON Web Token (JWT) containing claims about

        permissions and expiration time.


        **Token Expiration:** Tokens typically expire in 900 seconds (15 minutes). The exact

        expiration time can be found in:

        - The `expires_in` field (seconds until expiration)

        - The `exp` claim in the decoded JWT (Unix timestamp)'
      operationId: generateAccessToken
      requestBody:
        required: true
        content:
          application/x-www-form-urlencoded:
            schema:
              type: object
              properties:
                grant_type:
                  type: string
                  enum:
                  - client_credentials
                  description: The OAuth 2.0 grant type. Only 'client_credentials' is supported.
                client_id:
                  type: string
                  description: Your application's client identifier. Obtain from Infinity administration.
                  example: messaging-api-123e4567-e89b-12d3-a456-426614174000
                client_secret:
                  type: string
                  description: Your application's client secret. Keep this secure and never expose in client-side code.
                  example: dFdiohFsZXCamxUmRS680KiQBqmnu6Y9
              required:
              - grant_type
              - client_id
              - client_secret
            examples:
              Generate Access Token:
                $ref: '#/components/examples/GenerateAccessToken'
      responses:
        '200':
          description: Successfully generated access token
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccessTokenResponse'
              examples:
                Generate Access Token Response:
                  $ref: '#/components/examples/GenerateAccessTokenResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
      deprecated: false
      security:
      - {}
    servers:
    - url: https://core.{customer-subdomain}.ec.avayacloud.com/auth/realms/avaya
      description: Avaya Infinity Authentication
      variables:
        customer-subdomain:
          default: avaya1234
          description: Your Infinity instance subdomain (e.g., avaya1234, acme-corp-prod)
components:
  schemas:
    ResourceOwnerPasswordRequest:
      type: object
      description: request payload
      properties:
        grant_type:
          type: string
          example: password
        client_id:
          type: string
          example: client_id
        client_secret:
          type: string
          example: client_secret
        username:
          type: string
          format: string
          example: user-account
        password:
          type: string
          format: string
          example: password1
      required:
      - grant_type
      - client_id
      - client_secret
      - username
      - password
    RefreshTokenRequest:
      type: object
      description: request payload
      properties:
        grant_type:
          type: string
          example: refresh_token
        client_id:
          type: string
          example: client_id
        client_secret:
          type: string
          example: client_secret
        refresh_token:
          description: Input refresh token acquired from previous generate access token response
          type: string
          example: eyJhbGciOiJIUzI1...
      required:
      - grant_type
      - client_id
      - client_secret
      - refresh_token
    GenerateTokenRequest:
      type: object
      description: reuest payload
      properties:
        grant_type:
          type: string
          example: client_credentials
        client_id:
          type: string
          example: client_id
        client_secret:
          type: string
          example: client_secret
      required:
      - grant_type
      - client_id
      - client_secret
    GenerateTokenResponse:
      description: Generate token response.
      type: object
      properties:
        access_token:
          description: Access tokens are used in token-based authentication to allow an application to access an API
          type: string
          example: eett4g66678jgde....
        expires_in:
          description: It displayes time in sec
          type: integer
          format: int32
          example: 900
        refresh_token:
          description: Displays new refresh token
          type: string
          example: eyJhbGciOiJIUzI1...
    Problem:
      type: object
      description: '<b>Problem Detail</b> as a way to carry machine-readable details of errors in a HTTP response to avoid the need to define new error response formats for HTTP APIs <a href="https://tools.ietf.org/html/rfc7807">RFC 7807</a>

        '
      properties:
        type:
          type: string
          format: uri
          description: 'An absolute URI that identifies the problem type. When dereferenced, it SHOULD provide human-readable documentation for the problem type (e.g., using HTML).

            '
          default: about:blank
          example: https://developers.avayacloud.com/onecloud-ccaas/docs/error-handling#constraint-violation
        title:
          type:
          - string
          - 'null'
          description: 'A short, summary of the problem type. Written in english and readable for engineers (usually not suited for non technical stakeholders and not localized).

            '
          example: Service Unavailable
        status:
          type:
          - integer
          - 'null'
          format: int32
          description: 'The HTTP status code generated by the origin server for this occurrence of the problem.

            '
          minimum: 100
          example: 503
          exclusiveMaximum: 600
        detail:
          type:
          - string
          - 'null'
          description: 'A human readable explanation specific to this occurrence of the problem.

            '
          example: Connection to database timed out
        instance:
          type:
          - string
          - 'null'
          format: uri
          description: 'An absolute URI that identifies the specific occurrence of the problem. It may or may not yield further information if dereferenced.

            '
        violations:
          type:
          - array
          - 'null'
          description: 'A list of violations that occurred as a result of invalid data provided as part of a request.

            '
          items:
            type: object
            properties:
              field:
                type: string
                description: 'The name of the field in the request that caused the violation. This can be the name of a path parameter, query parameter, or a field within the request body.

                  '
                example: accountId
              message:
                type: string
                description: 'A human readable explanation specific to this occurrence of the violation.

                  '
                example: must match "^[a-zA-Z]{6}$"
              code:
                type: integer
                format: int32
                description: 'The violation code generated by the server for this occurrence of the violation. Use this code when implementing any error handling logic instead of the message, as the message can change.

                  '
                example: 20006
          example:
          - field: emailAddress
            message: must not be null
            code: 20002
          - field: accountId
            message: must match "^[a-zA-Z]{6}$"
            code: 20006
    ErrorResponse:
      type: object
      description: Error response
      required:
      - error
      properties:
        error:
          type: string
          description: Error code
          example: invalid_client
        error_description:
          type: string
          description: Human-readable error description
          example: Invalid client or Invalid client credentials
    AccessTokenResponse:
      type: object
      description: Successful access token response
      required:
      - access_token
      - expires_in
      - token_type
      properties:
        access_token:
          type: string
          description: 'JWT access token to use in Authorization: Bearer {token} header'
          example: eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...
        expires_in:
          type: integer
          description: Token validity duration in seconds (typically 900 seconds / 15 minutes)
          example: 900
        token_type:
          type: string
          description: Token type - always 'Bearer'
          example: Bearer
        scope:
          type: string
          description: OAuth scopes granted with this token
          example: email profile
  examples:
    ErrorNotFound:
      description: Not Found
      value:
        type: https://developers.avayacloud.com/onecloud-ccaas/docs/error-handling#not-found
        title: Not Found
        status: 404
        detail: Either there is no API method associated with the URL path of the request, or the request refers to one or more resources that were not found.
    ErrorUnsupportedMediaType:
      description: Unsupported Media Type
      value:
        type: https://developers.avayacloud.com/onecloud-ccaas/docs/error-handling#conflict
        title: Conflict
        status: 415
        detail: The media-type in Content-type of the request is not supported by the server.
    ErrorForbidden:
      description: Forbidden
      value:
        type: https://developers.avayacloud.com/onecloud-ccaas/docs/error-handling#forbidden
        title: Forbidden
        status: 403
        detail: According to the access control policy the current user and/or accountId does not have permission to access this resource.
    ErrorUnauthorized:
      description: Unauthorized
      value:
        type: https://developers.avayacloud.com/onecloud-ccaas/docs/error-handling#unauthorized
        title: Unauthorized
        status: 401
        detail: This operation requires authentication. See https://developers.avayacloud.com/onecloud-ccaas/docs/how-to-authenticate-with-ccaas-apis
    ErrorConstraintViolation:
      description: Constraint Violation
      value:
        type: https://developers.avayacloud.com/onecloud-ccaas/docs/error-handling#constraint-violation
        title: Constraint Violation
        status: 400
        detail: A problem that indicates a syntactically correct, yet semantically illegal request. The Server can not process this request until the client resolves the semantic errors described in the violations section.
    ErrorConflict:
      description: Conflict
      value:
        type: https://developers.avayacloud.com/onecloud-ccaas/docs/error-handling#conflict
        title: Conflict
        status: 409
        detail: Indicates that the resource the client is trying to create already exists or some conflict when processing the request.
    ErrorInternalServerError:
      description: Server Error
      value:
        type: https://developers.avayacloud.com/onecloud-ccaas/docs/error-handling#server-error
        title: Server Error
        status: 500
        detail: An internal server error was encountered.
    GenerateAccessToken:
      summary: Generate access token request
      value:
        grant_type: client_credentials
        client_id: messaging-api-123e4567-e89b-12d3-a456-426614174000
        client_secret: dFdiohFsZXCamxUmRS680KiQBqmnu6Y9
    ErrorUnauthorized_2:
      summary: Invalid credentials
      value:
        error: invalid_client
        error_description: Invalid client or Invalid client credentials
    GenerateAccessTokenResponse:
      summary: Successful token generation
      value:
        access_token: eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...
        expires_in: 900
        token_type: Bearer
        scope: email profile
    ErrorConstraintViolation_2:
      summary: Unsupported grant type
      value:
        error: unsupported_grant_type
        error_description: Unsupported grant type. Only 'client_credentials' is supported.
  parameters:
    accountId:
      name: accountId
      in: path
      description: The unique 6 character internal id that represents the customer account
      required: true
      schema:
        type: string
        minLength: 6
        maxLength: 6
        pattern: ^[a-zA-Z]{6}$
        example: ABCDEF
  responses:
    Unauthorized:
      description: Unauthorized - Invalid client credentials
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            Invalid Credentials:
              $ref: '#/components/examples/ErrorUnauthorized_2'
    BadRequest:
      description: Bad Request - Invalid request format or unsupported grant type
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            Unsupported Grant Type:
              $ref: '#/components/examples/ErrorConstraintViolation_2'
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: appkey
x-refined-from:
- avaya-axp-auth-openapi-original.json
- avaya-infinity-access-token-openapi-original.json
x-explorer-enabled: false
x-samples-languages:
- curl
- node
- java
- javascript
- python
- go