> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.ninjatrader.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ninjatrader.com/_mcp/server.

# O Auth Token

POST https://demo.tradovateapi.com/v1/auth/oauthtoken
Content-Type: application/json

### Exchange an OAuth authorization code for an access token.

**Available to:** Anyone with valid OAuth client credentials (no access token required)

**Environments:** Demo, Live

**[Rate Limit](/api/authentication#request-rate-limits-and-time-penalties):** 10 requests per hour, 30-second back-off, counts failed requests only

The final step of the [OAuth authorization-code flow](/api/oauth). After a user approves your application and you receive a single-use authorization `code` at your redirect URI, exchange that code here for an access token.

Send a form-encoded request with `grant_type` set to `authorization_code`, the `client_id` and `client_secret` issued to your application by NinjaTrader, the same `redirect_uri` you used to start the flow, and the `code` you received. On success, the response contains an `access_token` and `expires_in` (its lifetime in seconds); send the token with the `Bearer` scheme on subsequent requests.

[Source Content Needed: how a developer requests OAuth client credentials from NinjaTrader.]

<Note>
Other grant types (such as `client_credentials` and `jwt-bearer`) are used for server-to-server and Connect integrations and are documented in the Connect docs, not here.
</Note>

**Common Failure Scenarios**

- The authorization `code` has expired or was already used — codes are single-use.
- The `redirect_uri` does not match the one used to obtain the code.
- The `client_id` or `client_secret` is missing or incorrect.

On failure, the response omits `access_token` and instead returns the `error` and `error_description` fields (OAuth 2.0 standard), rather than an `errorText` field.

**Error Messages**

| `error` | Trigger |
|---------|---------|
| `invalid_grant` | The authorization code is expired, already used, or does not match the `redirect_uri`. |
| `invalid_client` | The `client_id` or `client_secret` is missing or incorrect. |

Reference: https://docs.ninjatrader.com/api/rest-api-endpoints/authentication/o-auth-token

## OpenAPI Specification

```yaml
openapi: 3.1.0
info:
  title: public
  version: 1.0.0
paths:
  /auth/oauthtoken:
    post:
      operationId: oAuthToken
      summary: O Auth Token
      description: >-
        ### Exchange an OAuth authorization code for an access token.


        **Available to:** Anyone with valid OAuth client credentials (no access
        token required)


        **Environments:** Demo, Live


        **[Rate
        Limit](/api/authentication#request-rate-limits-and-time-penalties):** 10
        requests per hour, 30-second back-off, counts failed requests only


        The final step of the [OAuth authorization-code flow](/api/oauth). After
        a user approves your application and you receive a single-use
        authorization `code` at your redirect URI, exchange that code here for
        an access token.


        Send a form-encoded request with `grant_type` set to
        `authorization_code`, the `client_id` and `client_secret` issued to your
        application by NinjaTrader, the same `redirect_uri` you used to start
        the flow, and the `code` you received. On success, the response contains
        an `access_token` and `expires_in` (its lifetime in seconds); send the
        token with the `Bearer` scheme on subsequent requests.


        [Source Content Needed: how a developer requests OAuth client
        credentials from NinjaTrader.]


        <Note>

        Other grant types (such as `client_credentials` and `jwt-bearer`) are
        used for server-to-server and Connect integrations and are documented in
        the Connect docs, not here.

        </Note>


        **Common Failure Scenarios**


        - The authorization `code` has expired or was already used — codes are
        single-use.

        - The `redirect_uri` does not match the one used to obtain the code.

        - The `client_id` or `client_secret` is missing or incorrect.


        On failure, the response omits `access_token` and instead returns the
        `error` and `error_description` fields (OAuth 2.0 standard), rather than
        an `errorText` field.


        **Error Messages**


        | `error` | Trigger |

        |---------|---------|

        | `invalid_grant` | The authorization code is expired, already used, or
        does not match the `redirect_uri`. |

        | `invalid_client` | The `client_id` or `client_secret` is missing or
        incorrect. |
      tags:
        - Authentication
      responses:
        '200':
          description: OAuthTokenResponse
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthTokenResponse'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/OAuthToken'
servers:
  - url: https://demo.tradovateapi.com/v1
    description: Demo
  - url: https://live.tradovateapi.com/v1
    description: Live
components:
  schemas:
    OAuthToken:
      type: object
      properties:
        grant_type:
          type: string
        code:
          type: string
        redirect_uri:
          type: string
        client_id:
          type: string
        client_secret:
          type: string
        httpAuth:
          type: string
        refresh_token:
          type: string
        code_verifier:
          type: string
        resource:
          type: string
        assertion:
          type: string
      required:
        - grant_type
      title: OAuthToken
    OAuthTokenResponse:
      type: object
      properties:
        access_token:
          type: string
        refresh_token:
          type: string
        token_type:
          type: string
        expires_in:
          type: integer
        refresh_token_expires_in:
          type: integer
        error:
          type: string
        error_description:
          type: string
        id_token:
          type: string
      title: OAuthTokenResponse

```

## Examples



**Request**

```json
{
  "grant_type": "string"
}
```

**Response**

```json
{
  "access_token": "string",
  "refresh_token": "string",
  "token_type": "string",
  "expires_in": 1,
  "refresh_token_expires_in": 1,
  "error": "string",
  "error_description": "string",
  "id_token": "string"
}
```

**SDK Code**

```python
import requests

url = "https://demo.tradovateapi.com/v1/auth/oauthtoken"

payload = { "grant_type": "string" }
headers = {"Content-Type": "application/json"}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript
const url = 'https://demo.tradovateapi.com/v1/auth/oauthtoken';
const options = {
  method: 'POST',
  headers: {'Content-Type': 'application/json'},
  body: '{"grant_type":"string"}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://demo.tradovateapi.com/v1/auth/oauthtoken"

	payload := strings.NewReader("{\n  \"grant_type\": \"string\"\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://demo.tradovateapi.com/v1/auth/oauthtoken")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n  \"grant_type\": \"string\"\n}"

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://demo.tradovateapi.com/v1/auth/oauthtoken")
  .header("Content-Type", "application/json")
  .body("{\n  \"grant_type\": \"string\"\n}")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://demo.tradovateapi.com/v1/auth/oauthtoken', [
  'body' => '{
  "grant_type": "string"
}',
  'headers' => [
    'Content-Type' => 'application/json',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://demo.tradovateapi.com/v1/auth/oauthtoken");
var request = new RestRequest(Method.POST);
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"grant_type\": \"string\"\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = ["Content-Type": "application/json"]
let parameters = ["grant_type": "string"] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://demo.tradovateapi.com/v1/auth/oauthtoken")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```