Authorization code flow with refresh token (confidential clients)
1
3
Last updated
Use this flow when: Your application can securely store a Client Secret (server-side applications).
Benefits: Provides both access tokens and refresh tokens for long-term access.
Redirect the user to the authorization endpoint:
GET https://www.make.com/oauth/v2/authorizeRequired parameters:
client_id: Your application's Client ID
response_type: Set to code
redirect_uri: Pre-registered callback URL
scope: Requested permissions (include openid for OpenID Connect)
state: Random string for CSRF protection (recommended)
Example URL:
https://www.make.com/oauth/v2/authorize? client_id=your_client_id& response_tyMake a server-side POST request to the token endpoint:
POST https://www.make.com/oauth/v2/tokenRequired Parameters:
client_id: Your Client ID
client_secret: Your Client Secret
grant_type: Set to authorization_code
code: Authorization code from Step 2
Response:
json{ "access_token": "eyJ...", "refresh_token": "eyJ...", "id_token": "eyJ...", "token_type": "Bearer", "expires_in": 3600}Last updated

