POST /oauth/convert

Required authentication: Application
Supported formats: json

Exchanges an OAuth code for a full OAuth grant object. The returned object will contain the grant_secret that you should use for future requests inside the Authorization header for that account.

Each code expires in 5 minutes, and can only be used once. Repeated requests sent to this method with the same code will fail.

Ensure that you save both the grant_id and the grant_secret you receive, as well as recording any other data in the object that your application needs to run, such as the information inside the account object.

Parameter Type Atn Details
code String The grant code from the previous step in the OAuth workflow.

Example Requests

Exchange an OAuth code for a grant object:

POST https://api.scryfall.com/oauth/convert
Host: api.scryfall.com
Content-Type: application/json
Authorization: Bearer cs-ExampleSecret

{
  "code": "gc-l2VPxm33NzpYbJheqsALFevJJ7AXU8za"
}
HTTP/1.1 200 OK
Content-Type: application/json; charset=UTF-8

{
  "object": "oauth_grant",
  "grant_id": "d3e6f2b4-e732-4c6d-8200-4e049bae4c09",
  "created_at": "2018-09-23T03:33:16-04:00",
  "scope": "read",
  "grant_secret": "gs-cAXqb2A4r0EkGtXKxbpKdMR9gaMhMnDT",
  "revoked": false,
  "account": {
    "object": "scryfall_account",
    "id": "79602aac-d480-4669-93f8-26c21a771219",
    "username": "amoeboi",
    "display_name": "Amoeboid Changeling",
    "twitter": "wizards_magic",
    "full_featured": true,
    "verified": false
  }
}