Exchange auth code or refresh token for access token
curl --request POST \
--url https://api.profy.cn/oauth/token \
--header 'Content-Type: application/json' \
--data '
{
"client_id": "<string>",
"client_secret": "<string>",
"code": "<string>",
"redirect_uri": "<string>",
"refresh_token": "<string>"
}
'import requests
url = "https://api.profy.cn/oauth/token"
payload = {
"client_id": "<string>",
"client_secret": "<string>",
"code": "<string>",
"redirect_uri": "<string>",
"refresh_token": "<string>"
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
client_id: '<string>',
client_secret: '<string>',
code: '<string>',
redirect_uri: '<string>',
refresh_token: '<string>'
})
};
fetch('https://api.profy.cn/oauth/token', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.profy.cn/oauth/token",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'client_id' => '<string>',
'client_secret' => '<string>',
'code' => '<string>',
'redirect_uri' => '<string>',
'refresh_token' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.profy.cn/oauth/token"
payload := strings.NewReader("{\n \"client_id\": \"<string>\",\n \"client_secret\": \"<string>\",\n \"code\": \"<string>\",\n \"redirect_uri\": \"<string>\",\n \"refresh_token\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.profy.cn/oauth/token")
.header("Content-Type", "application/json")
.body("{\n \"client_id\": \"<string>\",\n \"client_secret\": \"<string>\",\n \"code\": \"<string>\",\n \"redirect_uri\": \"<string>\",\n \"refresh_token\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.profy.cn/oauth/token")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"client_id\": \"<string>\",\n \"client_secret\": \"<string>\",\n \"code\": \"<string>\",\n \"redirect_uri\": \"<string>\",\n \"refresh_token\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"access_token": "<string>",
"token_type": "Bearer",
"expires_in": 3600,
"refresh_token": "<string>",
"scope": "<string>"
}OAuth
交换 Token
Supports both application/json and application/x-www-form-urlencoded. Use grant_type=authorization_code to exchange an auth code, or grant_type=refresh_token to refresh an expired access token.
POST
/
oauth
/
token
Exchange auth code or refresh token for access token
curl --request POST \
--url https://api.profy.cn/oauth/token \
--header 'Content-Type: application/json' \
--data '
{
"client_id": "<string>",
"client_secret": "<string>",
"code": "<string>",
"redirect_uri": "<string>",
"refresh_token": "<string>"
}
'import requests
url = "https://api.profy.cn/oauth/token"
payload = {
"client_id": "<string>",
"client_secret": "<string>",
"code": "<string>",
"redirect_uri": "<string>",
"refresh_token": "<string>"
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
client_id: '<string>',
client_secret: '<string>',
code: '<string>',
redirect_uri: '<string>',
refresh_token: '<string>'
})
};
fetch('https://api.profy.cn/oauth/token', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.profy.cn/oauth/token",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'client_id' => '<string>',
'client_secret' => '<string>',
'code' => '<string>',
'redirect_uri' => '<string>',
'refresh_token' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.profy.cn/oauth/token"
payload := strings.NewReader("{\n \"client_id\": \"<string>\",\n \"client_secret\": \"<string>\",\n \"code\": \"<string>\",\n \"redirect_uri\": \"<string>\",\n \"refresh_token\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.profy.cn/oauth/token")
.header("Content-Type", "application/json")
.body("{\n \"client_id\": \"<string>\",\n \"client_secret\": \"<string>\",\n \"code\": \"<string>\",\n \"redirect_uri\": \"<string>\",\n \"refresh_token\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.profy.cn/oauth/token")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"client_id\": \"<string>\",\n \"client_secret\": \"<string>\",\n \"code\": \"<string>\",\n \"redirect_uri\": \"<string>\",\n \"refresh_token\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"access_token": "<string>",
"token_type": "Bearer",
"expires_in": 3600,
"refresh_token": "<string>",
"scope": "<string>"
}client_id 和 client_secret 必须在请求体中传递,不支持 Basic Auth Header。使用场景
1. 用授权码换取 Token
用户在授权页面同意后,你的redirect_uri 会收到 code 参数。用它换取 access token:
curl --request POST \
--url https://app.profy.cn/oauth/token \
--header 'Content-Type: application/json' \
--data '{
"grant_type": "authorization_code",
"code": "从回调 URL 拿到的授权码",
"redirect_uri": "https://your-app.com/callback",
"client_id": "你的应用 UUID",
"client_secret": "你的应用密钥"
}'
2. 用 Refresh Token 续期
Access token 有效期 1 小时。过期后用 refresh token 获取新的 token 对:curl --request POST \
--url https://app.profy.cn/oauth/token \
--header 'Content-Type: application/json' \
--data '{
"grant_type": "refresh_token",
"refresh_token": "之前获取的 refresh_token",
"client_id": "你的应用 UUID",
"client_secret": "你的应用密钥"
}'
Refresh token 每次使用后会自动轮换(rotation),旧 token 立即失效。请务必保存响应中返回的新
refresh_token。常见错误
| 错误 | 原因 |
|---|---|
Missing client credentials | 请求体缺少 client_id 或 client_secret |
Invalid client credentials | client_id 不存在或 client_secret 不匹配 |
Invalid or expired authorization code | 授权码已过期(5 分钟有效)或已被使用 |
redirect_uri mismatch | redirect_uri 与授权请求时的不一致 |
Invalid or expired refresh token | Refresh token 无效、已过期(90 天)或已被轮换 |
请求体
application/json
可用选项:
authorization_code, refresh_token Application UUID
Application secret
Authorization code (required for authorization_code grant)
Must match the original authorization request
Refresh token (required for refresh_token grant)

