> ## Documentation Index
> Fetch the complete documentation index at: https://docs.summerengine.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Exchange a code or refresh token for a player MCP access token

> application/x-www-form-urlencoded, no client authentication.



## OpenAPI

````yaml scripts/reference/sources/openapi/player.json POST /v1/oauth/token
openapi: 3.1.0
info:
  title: Summer Player Game Platform API
  version: summer.player.games/v1
  description: >-
    Public Summer Games store reads, the connected-app OAuth endpoints, and the
    signed-in player's profile and preferences.
servers:
  - url: https://api.summer.games
security:
  - playerBearer: []
paths:
  /v1/oauth/token:
    post:
      summary: Exchange a code or refresh token for a player MCP access token
      description: >-
        application/x-www-form-urlencoded, no client authentication. grant_type
        authorization_code needs code, redirect_uri, client_id and
        code_verifier; refresh_token needs refresh_token and client_id and may
        narrow scope. resource, when sent, must be the MCP resource. The access
        token is an account token for client summer-mcp (five minutes) naming
        its grant and scopes. Refresh tokens rotate; reusing one revokes the
        grant. Errors use the RFC 6749 body {error, error_description}.
      operationId: exchangeOAuthToken
      responses:
        '200':
          description: Tokens. Never cache them.
          content:
            application/json:
              schema:
                type: object
                required:
                  - access_token
                  - token_type
                  - expires_in
                  - refresh_token
                  - scope
                properties:
                  access_token:
                    type: string
                  token_type:
                    const: Bearer
                  expires_in:
                    type: integer
                  refresh_token:
                    type: string
                  scope:
                    type: string
        '400':
          description: >-
            invalid_request, invalid_grant, invalid_scope, invalid_target or
            unsupported_grant_type
        '401':
          description: invalid_client (a client secret was sent)
        '429':
          description: Token budget spent; honour Retry-After
        '503':
          description: temporarily_unavailable
      security: []
components:
  securitySchemes:
    playerBearer:
      type: http
      scheme: bearer
      description: >-
        A player access token. Store reads need no token. Other apps get a token
        through connected-app OAuth: register the client, let the player approve
        it on summer.games, then exchange the code at the token endpoint.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.