Skip to content
Proud to collaborate with Microsoft for Startups

mercadopago.oauth.create-oauth-token ​

Exchanges authorization codes for access tokens, refreshes expired tokens, or requests client credentials tokens for machine-to-machine flows. Security notes: - The state parameter is mandatory for authorization_code flows to prevent CSRF. - Store refresh tokens in server-side encrypted storage — never in localStorage. - Rotate client_secret regularly and store in a secrets manager.

Create OAuth token

Overview ​

PropertyValue
Workflow typeAtomic
LibraryApp-mercadopago
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
base_urlstringYes—Mercadopago API root, e.g. https://<host>/api
api_tokenstringNo—Bearer token; omit to use the workflow's token env var
client_idstringYes—Your application's client ID
client_secretstringYes—Your application's client secret. Never expose in client-side code. Store in a secrets manager.
grant_typestringYes—OAuth 2.0 grant type
codestringNo—Authorization code from the OAuth redirect (authorization_code flow)
redirect_uristringNo—Must match the registered redirect URI exactly
code_verifierstringNo—PKCE code verifier (recommended for mobile/SPA)
refresh_tokenstringNo—Refresh token for the refresh_token grant

Output Schema ​

FieldTypeRequiredDefaultDescription
base_urlstringYes—Mercadopago API root, e.g. https://<host>/api
api_tokenstringNo—Bearer token; omit to use the workflow's token env var
client_idstringYes—Your application's client ID
client_secretstringYes—Your application's client secret. Never expose in client-side code. Store in a secrets manager.
grant_typestringYes—OAuth 2.0 grant type
codestringNo—Authorization code from the OAuth redirect (authorization_code flow)
redirect_uristringNo—Must match the registered redirect URI exactly
code_verifierstringNo—PKCE code verifier (recommended for mobile/SPA)
refresh_tokenstringNo—Refresh token for the refresh_token grant
status_codeintegerNo—HTTP status code of the completed call
responsejsonNo—Parsed JSON response body
failure_reasonstringNo——
failure_typestringNo——
failed_atstringNo——
failed_stepstringNo——
failed_layerstringNo——
failed_at_statestringNo——
errorstringNo——
error_typestringNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—executeWaiting to call POST /oauth/token
completedNoYesYes—HTTP call succeeded
failedNoYesNo—HTTP call failed

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompletedPerform POST /oauth/token
* (any state)failfailedRecord the failure reason

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "mercadopago.oauth.create-oauth-token",
  "initial_data": {
    "base_url": "value",
    "client_id": "value",
    "client_secret": "value",
    "grant_type": "value"
  }
}