mercadopago.oauth.create-oauth-token
Exchanges authorization codes for access tokens, refreshes expired tokens, or requests client credentials tokens for machine-to-machine flows. Security notes: - The state parameter is mandatory for authorization_code flows to prevent CSRF. - Store refresh tokens in server-side encrypted storage — never in localStorage. - Rotate client_secret regularly and store in a secrets manager.
Create OAuth token
Overview
| Property | Value |
|---|---|
| Workflow type | Atomic |
| Library | App-mercadopago |
| Version | 1.0 |
Input Schema
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
base_url | string | Yes | — | Mercadopago API root, e.g. https://<host>/api |
api_token | string | No | — | Bearer token; omit to use the workflow's token env var |
client_id | string | Yes | — | Your application's client ID |
client_secret | string | Yes | — | Your application's client secret. Never expose in client-side code. Store in a secrets manager. |
grant_type | string | Yes | — | OAuth 2.0 grant type |
code | string | No | — | Authorization code from the OAuth redirect (authorization_code flow) |
redirect_uri | string | No | — | Must match the registered redirect URI exactly |
code_verifier | string | No | — | PKCE code verifier (recommended for mobile/SPA) |
refresh_token | string | No | — | Refresh token for the refresh_token grant |
Output Schema
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
base_url | string | Yes | — | Mercadopago API root, e.g. https://<host>/api |
api_token | string | No | — | Bearer token; omit to use the workflow's token env var |
client_id | string | Yes | — | Your application's client ID |
client_secret | string | Yes | — | Your application's client secret. Never expose in client-side code. Store in a secrets manager. |
grant_type | string | Yes | — | OAuth 2.0 grant type |
code | string | No | — | Authorization code from the OAuth redirect (authorization_code flow) |
redirect_uri | string | No | — | Must match the registered redirect URI exactly |
code_verifier | string | No | — | PKCE code verifier (recommended for mobile/SPA) |
refresh_token | string | No | — | Refresh token for the refresh_token grant |
status_code | integer | No | — | HTTP status code of the completed call |
response | json | No | — | Parsed JSON response body |
failure_reason | string | No | — | — |
failure_type | string | No | — | — |
failed_at | string | No | — | — |
failed_step | string | No | — | — |
failed_layer | string | No | — | — |
failed_at_state | string | No | — | — |
error | string | No | — | — |
error_type | string | No | — | — |
States
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
pending | Yes | No | — | execute | Waiting to call POST /oauth/token |
completed | No | Yes | Yes | — | HTTP call succeeded |
failed | No | Yes | No | — | HTTP call failed |
State Diagram
Transitions
| From | Action | To | Description |
|---|---|---|---|
pending | execute | completed | Perform POST /oauth/token |
* (any state) | fail | failed | Record the failure reason |
API Usage
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "mercadopago.oauth.create-oauth-token",
"initial_data": {
"base_url": "value",
"client_id": "value",
"client_secret": "value",
"grant_type": "value"
}
}