# Exchange an authentication token

Exchanges an authentication token for a JWT.


By default, this operation invalidates the exchanged authentication token.

Endpoint: POST /authentication-tokens/{token}/exchange
Version: latest
Security: SecretApiKey, JWT, PublishableApiKey

## Security:

  - `SecretApiKey` (unknown)
    apiKey in header REB-APIKEY

  - `JWT` (unknown)
    http bearer JWT

  - `PublishableApiKey` (unknown)
    apiKey in header Authorization

## Path parameters:

  - `token` (string, required)
    ID of the authentication token.

## Request fields (application/json):

  - `invalidate` (boolean)
    Specifies if the token must be invalidated after the exchange is performed.
    Example: true

  - `oneTimePassword` (string)
    One-time password that is sent by email.
This value must contain digits only.
    Example: 123456

  - `customerId` (string)
    ID of the customer resource.
    Example: cus_0YV7DDSDD1C8DA64KHH2W33CPF

  - `acl` (array)
    Access Control List (ACL) information.

  - `acl.scope` (object, required)
    Example: {"organizationId":["organizationId-id-1"]}

  - `acl.scope.organizationId` (array)
    Array of account IDs.

  - `acl.scope.productId` (array)
    Array of product IDs.

  - `acl.scope.planId` (array)
    Array of plan IDs.

  - `acl.scope.customFieldName` (array)
    Array of custom field names.

  - `acl.permissions` (array, required)
    Example: ["PostFile","StorefrontGetAccount","StorefrontGetWebsite","StorefrontGetKycDocument","StorefrontPostKycDocument"]

  - `customClaims` (object)
    Example: {"documents":["identity-proof","address-proof"],"redirectUrl":"https://mywebsite.com"}

  - `expiredTime` (string)
    Date and time when the session expires.
The default value is one hour after the `createdTime` value.

## Response 201:

  - `201` (unknown)
    Authentication token exchanged for a JWT.

## Response 201 fields (application/json):

  - `id` (string)
    ID of the session.
    Example: jwt_0YV7DEJX80CDRAKVTV478ZNJDR

  - `type` (string)
    Type of session.
    Enum: "customer"

  - `token` (string)
    Token used for authentication.

  - `customerId` (string)
    ID of the customer resource.
    Example: cus_0YV7DDSDD1C8DA64KHH2W33CPF

  - `acl` (array)
    Access Control List (ACL) information.

  - `acl.scope` (object, required)
    Example: {"organizationId":["organizationId-id-1"]}

  - `acl.scope.organizationId` (array)
    Array of account IDs.

  - `acl.scope.productId` (array)
    Array of product IDs.

  - `acl.scope.planId` (array)
    Array of plan IDs.

  - `acl.scope.customFieldName` (array)
    Array of custom field names.

  - `acl.permissions` (array, required)
    Example: ["PostFile","StorefrontGetAccount","StorefrontGetWebsite","StorefrontGetKycDocument","StorefrontPostKycDocument"]

  - `customClaims` (object)
    Example: {"documents":["identity-proof","address-proof"],"redirectUrl":"https://mywebsite.com"}

  - `createdTime` (string)
    Date and time when the resource is created.
This value is set automatically when the resource is created.

  - `updatedTime` (string)
    Date and time when the resource is updated.
This value is set automatically when the resource is updated.

  - `expiredTime` (string)
    Date and time when the session expires.
The default value is one hour after the `createdTime` value.

  - `_links` (array)
    Related links.

  - `_links.href` (string)
    Link URL.

  - `_links.rel` (string)
    Type of link.
    Enum: "customer"

## Response 201 headers (application/json):

  - `Location` (string)
    Location of the related resource.
    Example: https://api.rebilly.com/example

  - `X-RateLimit-Limit` (integer)
    Total number of rate limit tokens for this request within a rate limit period.
For more information, see [Rate limits](#section/Rate-limits).
    Example: 3600

  - `X-RateLimit-Remaining` (integer)
    Remaining number of rate limit tokens for this request within the rate limit period. 
For example, in the sandbox environment, rate limits for non-GET endpoints are set at 3000 requests per 10 minutes.
    Example: 3600

## Response 401:

  - `401` (unknown)
    Unauthorized access.
Invalid credentials used.

## Response 401 fields (application/json):

  - `status` (integer)
    HTTP status code.

  - `type` (string)
    Problem type in the form of a [URI](https://tools.ietf.org/html/rfc3986) reference.
It should provide human-readable documentation for the problem type.
When this member is not present, its value is assumed to be "about:blank".

  - `title` (string)
    Short, human-readable summary of the problem type.
Other than for the purposes of localization, this should not change from occurrence to occurrence of the problem.

  - `detail` (string)
    Human-readable explanation that is specific to this occurrence of the problem.

  - `instance` (string)
    URI reference that identifies the specific occurrence of the problem.
It may or may not yield further information if dereferenced.

## Response 403:

  - `403` (unknown)
    Access forbidden.

## Response 403 fields (application/json):

  - `status` (integer)
    HTTP status code.

  - `type` (string)
    Problem type in the form of a [URI](https://tools.ietf.org/html/rfc3986) reference.
It should provide human-readable documentation for the problem type.
When this member is not present, its value is assumed to be "about:blank".

  - `title` (string)
    Short, human-readable summary of the problem type.
Other than for the purposes of localization, this should not change from occurrence to occurrence of the problem.

  - `detail` (string)
    Human-readable explanation that is specific to this occurrence of the problem.

  - `instance` (string)
    URI reference that identifies the specific occurrence of the problem.
It may or may not yield further information if dereferenced.

## Response 404:

  - `404` (unknown)
    Resource not found.

## Response 404 fields (application/json):

  - `status` (integer)
    HTTP status code.

  - `type` (string)
    Problem type in the form of a [URI](https://tools.ietf.org/html/rfc3986) reference.
It should provide human-readable documentation for the problem type.
When this member is not present, its value is assumed to be "about:blank".

  - `title` (string)
    Short, human-readable summary of the problem type.
Other than for the purposes of localization, this should not change from occurrence to occurrence of the problem.

  - `detail` (string)
    Human-readable explanation that is specific to this occurrence of the problem.

  - `instance` (string)
    URI reference that identifies the specific occurrence of the problem.
It may or may not yield further information if dereferenced.

## Response 429:

  - `429` (unknown)
    Request rate limit exceeded.

## Response 429 fields (application/json):

  - `type` (string)
    Problem type in the form of a [URI](https://tools.ietf.org/html/rfc3986) reference.
It should provide human-readable documentation for the problem type.
When this member is not present, its value is assumed to be "about:blank".
    Example: about:blank

  - `title` (string)
    Short, human-readable summary of the problem type.
Other than for the purposes of localization, this should not change from occurrence to occurrence of the problem.
    Example: Rate Limit Exceeded

  - `status` (integer)
    HTTP status code.

  - `detail` (string)
    Human-readable explanation that is specific to this occurrence of the problem.
    Example: A request cannot be executed because the user has sent too many requests within a certain period of time

  - `instance` (string)
    URI reference that identifies the specific occurrence of the problem.
It may or may not yield further information if dereferenced.

## Response 429 headers (application/json):

  - `X-RateLimit-Retry-After` (integer)
    UTC timestamp after which the rate limit resets and the request can be retried.
    Example: 1713187500

