Skip to main content
POST
Token Exchange

Body

application/json
provider
string
required

Slug of the configured external auth provider.

subject_token
string
required

The id_token (JWT) issued by the external provider.

subject_token_type
enum<string>

Optional. Field name borrowed from RFC 8693 — this is a Prisme.ai JSON login endpoint, not a full RFC 8693 token endpoint. When provided, must be urn:ietf:params:oauth:token-type:id_token (the only supported subject token type).

Available options:
urn:ietf:params:oauth:token-type:id_token
grant_type
enum<string>

Optional. Field name borrowed from RFC 8693. When provided, must be urn:ietf:params:oauth:grant-type:token-exchange.

Available options:
urn:ietf:params:oauth:grant-type:token-exchange
expiresAfter
number

Optional session expiration in seconds

Response

Success Response

firstName
string
required

Name

token
string
required

The minted Prisme.ai access token (JWT).

sessionId
string
required
email
string
Example:

"foo@prisme.ai"

status
enum<string>
Available options:
pending,
validated,
deactivated
language
string
authData
object
mfa
enum<string>

Current MFA method (super admin only).

Available options:
totp,
none,
*
meta
object
orgSlugs
string[]
platformRole
string
groupAcls
object
createdAt
string
updatedAt
string
updatedBy
string
lastName
string

Name

emailMasked
string

Partially masked email (e.g. "j***@acme.com"), returned to non-elevated callers in place of the clear-text email to disambiguate homonyms without exposing the full address.

photo
string

Profile picture URL

groups
string[]
identities
string[]

Denormalized ":" tuples (super admin only).

membership
object

Organization membership info (only returned when includeOrgMembership is set)

id
string

Unique id

expires
string
organizations
object[]

Organizations the user belongs to, as resolved at login. Same entries as GET /v2/me; the heavier org and permissions fields are not returned here.