> ## Documentation Index
> Fetch the complete documentation index at: https://docs.thefaithapp.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Exchange Hosted Auth Code

> Exchanges a one-time hosted auth code for a TheFaithApp member bearer token. Codes are short-lived, single-use, and bound to the redirect_uri used when auth started.



## OpenAPI

````yaml /api-reference/openapi.json post /v1/auth/token
openapi: 3.1.0
info:
  title: TheFaithApp Partner API
  version: 1.0.0
  description: >-
    The v1 API for third-party apps that sign in TheFaithApp members and access
    church-scoped content and workflows.
  contact:
    name: TheFaithApp Support
    email: support@thefaithapp.com
servers:
  - url: https://api.thefaithapp.com
    description: Production
security:
  - apiKeyAuth: []
    bearerAuth: []
tags:
  - name: Hosted Auth
    description: Sign members in through the hosted TheFaithApp authentication flow.
  - name: Core Experience
    description: Load member context and the personalized home experience.
  - name: Content
    description: >-
      Read sermons, media, YouTube videos, devotionals, and streaming
      configuration.
  - name: Engagement
    description: Manage member favorites and devotional bookmarks.
  - name: Churches
    description: Read church profiles, public directory records, and branch information.
  - name: Events & Volunteers
    description: >-
      Browse events and volunteer opportunities, then manage registrations and
      commitments.
  - name: Notifications & Bulletins
    description: Read church and member notifications and published bulletins.
  - name: Prayer
    description: Submit a prayer request for the authenticated member.
  - name: Member Connections
    description: Manage the member’s campus and ministry connections.
  - name: Community Groups
    description: >-
      Discover groups and manage membership, feeds, attendance, study guides,
      and leader notes.
  - name: Community Preferences & Research
    description: >-
      Manage community preferences, summaries, and consent-based research
      participation.
  - name: Resource Sharing
    description: Offer shared resources and manage member loan requests and transitions.
  - name: Mutual Aid
    description: >-
      Manage needs and offers, private responses, safety reports, and member
      activity.
  - name: Analytics
    description: Record product analytics events and retrieve aggregate metrics.
  - name: Notification Analytics
    description: Record and summarize notification delivery, open, and click events.
paths:
  /v1/auth/token:
    post:
      tags:
        - Hosted Auth
      summary: Exchange Hosted Auth Code
      description: >-
        Exchanges a one-time hosted auth code for a TheFaithApp member bearer
        token. Codes are short-lived, single-use, and bound to the redirect_uri
        used when auth started.
      operationId: postAuthToken
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                client_key:
                  type: string
                  description: Client key copied from Developer Access.
                  example: your-client-api-key
                code:
                  type: string
                  description: One-time code returned to your Redirect URL.
                  example: one-time-code
                redirect_uri:
                  type: string
                  format: uri
                  description: The same Redirect URL used in POST /v1/auth/start.
                  example: https://example.com/auth/callback
                code_verifier:
                  type: string
                  description: >-
                    Original PKCE code verifier when the auth flow started with
                    code_challenge.
                  example: original-random-code-verifier
              required:
                - client_key
                - code
                - redirect_uri
      responses:
        '200':
          description: Code exchanged for a member token.
          content:
            application/json:
              schema:
                type: object
                properties:
                  token_type:
                    type: string
                    example: Bearer
                  access_token:
                    type: string
                    example: member-bearer-token
                  expires_in:
                    type:
                      - integer
                      - 'null'
                    example: null
                  member:
                    type: object
                    properties:
                      id:
                        type: integer
                        example: 123
                      uuid:
                        type: string
                        example: member-user-id
                      name:
                        type:
                          - string
                          - 'null'
                        example: Jane Doe
                      email:
                        type:
                          - string
                          - 'null'
                        format: email
                        example: jane@example.com
                      client_id:
                        type: integer
                        example: 45
        '400':
          description: >-
            Code is invalid, expired, already used, or redirect_uri does not
            match.
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    example: Invalid or expired authorization code.
                  error:
                    type: string
                    example: Invalid or expired authorization code.
                  errors:
                    type: object
        '403':
          description: Redirect URL is not saved for this client key.
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    example: Redirect URL is not allowed for this client.
                  error:
                    type: string
                    example: Redirect URL is not allowed for this client.
                  errors:
                    type: object
        '404':
          description: Client key was not found.
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    example: Client not found.
                  error:
                    type: string
                    example: Client not found.
                  errors:
                    type: object
        '422':
          description: Validation error.
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    example: The code field is required.
                  error:
                    type: string
                    example: The code field is required.
                  errors:
                    type: object
      security: []
components:
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: X-API-Key
      description: >-
        Client API key copied from Developer Access in the TheFaithApp
        dashboard.
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: Sanctum
      description: Member access token returned by `POST /v1/auth/token`.

````