CreateOAuth2TokenResponseBody¶
Structure Class¶
CreateOAuth2TokenResponseBody
dataclass
¶
Response body payload for CreateOAuth2Token operation The response content depends on the grant_type from the request: - grant_type=authorization_code: Returns all fields including refresh_token and id_token - grant_type=refresh_token: Returns access_token, token_type, expires_in, refresh_token (no id_token)
Attributes¶
access_token
class-attribute
instance-attribute
¶
access_token: AccessToken = field(repr=False)
Scoped-down AWS credentials (15 minute duration) Present for both authorization code redemption and token refresh
expires_in
instance-attribute
¶
expires_in: int
Time to expiry in seconds (maximum 900) Present for both authorization code redemption and token refresh
id_token
class-attribute
instance-attribute
¶
id_token: str | None = None
ID token containing user identity information Present only in authorization code redemption response (grant_type=authorization_code) Not included in token refresh responses
refresh_token
class-attribute
instance-attribute
¶
Encrypted refresh token with cnf.jkt (SHA-256 thumbprint of presented jwk) Always present in responses (required for both flows)