curl --request POST \
--url https://sandbox.axle.insure/token/exchange \
--header 'Content-Type: application/json' \
--header 'x-client-id: <x-client-id>' \
--header 'x-client-secret: <api-key>' \
--data '
{
"authCode": "<string>"
}
'import requests
url = "https://sandbox.axle.insure/token/exchange"
payload = { "authCode": "<string>" }
headers = {
"x-client-id": "<x-client-id>",
"x-client-secret": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'x-client-id': '<x-client-id>',
'x-client-secret': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({authCode: '<string>'})
};
fetch('https://sandbox.axle.insure/token/exchange', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://sandbox.axle.insure/token/exchange",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'authCode' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-client-id: <x-client-id>",
"x-client-secret: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://sandbox.axle.insure/token/exchange"
payload := strings.NewReader("{\n \"authCode\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("x-client-id", "<x-client-id>")
req.Header.Add("x-client-secret", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://sandbox.axle.insure/token/exchange")
.header("x-client-id", "<x-client-id>")
.header("x-client-secret", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"authCode\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://sandbox.axle.insure/token/exchange")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-client-id"] = '<x-client-id>'
request["x-client-secret"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"authCode\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"success": true,
"data": {
"accessToken": "<string>",
"account": "<string>",
"policies": [
"<string>"
]
}
}{
"success": false,
"message": "Input validation failed due to one or more missing or invalid parameters. Review the request and try again."
}{
"success": false,
"message": "The authCode provided is not authorized. Potential issues include: expiration of the authCode, formatting issues, or use of an invalid authCode."
}{
"success": false,
"message": "This authCode has already been exchanged. For security reasons, each authCode can only be exchanged once."
}{
"message": "Too Many Requests"
}Exchange Token
Exchange an authorization code returned by an ignition.completed event for an access token. Follow the Quickstart or see Ignition Events for more details.
Auth codes are single-use and expire after 10 minutes, while access tokens do not expire.
curl --request POST \
--url https://sandbox.axle.insure/token/exchange \
--header 'Content-Type: application/json' \
--header 'x-client-id: <x-client-id>' \
--header 'x-client-secret: <api-key>' \
--data '
{
"authCode": "<string>"
}
'import requests
url = "https://sandbox.axle.insure/token/exchange"
payload = { "authCode": "<string>" }
headers = {
"x-client-id": "<x-client-id>",
"x-client-secret": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'x-client-id': '<x-client-id>',
'x-client-secret': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({authCode: '<string>'})
};
fetch('https://sandbox.axle.insure/token/exchange', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://sandbox.axle.insure/token/exchange",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'authCode' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-client-id: <x-client-id>",
"x-client-secret: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://sandbox.axle.insure/token/exchange"
payload := strings.NewReader("{\n \"authCode\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("x-client-id", "<x-client-id>")
req.Header.Add("x-client-secret", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://sandbox.axle.insure/token/exchange")
.header("x-client-id", "<x-client-id>")
.header("x-client-secret", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"authCode\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://sandbox.axle.insure/token/exchange")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-client-id"] = '<x-client-id>'
request["x-client-secret"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"authCode\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"success": true,
"data": {
"accessToken": "<string>",
"account": "<string>",
"policies": [
"<string>"
]
}
}{
"success": false,
"message": "Input validation failed due to one or more missing or invalid parameters. Review the request and try again."
}{
"success": false,
"message": "The authCode provided is not authorized. Potential issues include: expiration of the authCode, formatting issues, or use of an invalid authCode."
}{
"success": false,
"message": "This authCode has already been exchanged. For security reasons, each authCode can only be exchanged once."
}{
"message": "Too Many Requests"
}Authorizations
Your secret API key. This will be shared with you during onboarding and should be considered sensitive - it’s a password after all! Your secret will be matched with your client ID to authenticate your requests.
Headers
Your client ID. This will be shared with you during onboarding.
The client ID of the destination client. This is optional and only used by platform clients. See the Axle for Platforms guide for more information.
Body
The authorization code obtained after a user successfully connects their account via Ignition. Returned as a query parameter at the redirectUri.
Was this page helpful?