Skip to content
bucker

API reference

oauth

1 operation. Shapes are sketches of the declared schemas, bounded in depth — the authoritative document is linked from the index.

POST/oauth/token-exchange

No declared credential scheme

Reachable without a Bucker session token. RFC 8693 token exchange: `subject_token` in the body is the authentication, exactly as at any OAuth token endpoint.

Request body (required) · application/json

{
  grant_type: "urn:ietf:params:oauth:grant-type:token-exchange"
  subject_token: string
  subject_token_type?: "urn:ietf:params:oauth:token-type:access_token" | "urn:bucker:params:oauth:token-type:agent_token"
  resource: string
  scope?: string
  ttl_seconds?: integer
}

Response 200

{
  access_token: string
  issued_token_type: string
  token_type: "Bearer"
  expires_in: integer
  scope: string
  resource: string
  audience: string
}

Response 400 · `bad_request` — the path, query or body failed validation. `details` carries the Zod issues, one per offending field.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 429 · `rate_limited` or `quota_exceeded` — over a ceiling. `Retry-After` says when to come back, and `x-ratelimit-limit` / `-remaining` / `-reset` describe the bucket.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Response 500 · `internal_error` — an unhandled failure on this side. The message is always generic; `requestId` is the part worth quoting.

{
  error: {
    code: "bad_request" | "conflict" | "forbidden" | "internal_error" | "mfa_required" | "not_found" | "payload_too_large" | "quota_exceeded" | … 6 more
    message: string
    details?: unknown
    requestId?: string
  }
}

Request

curl -X POST https://api.bucker.io/oauth/token-exchange \
  -H 'content-type: application/json' \
  -d '{ … }'