> ## Documentation Index
> Fetch the complete documentation index at: https://developers.projectcor.com/llms.txt
> Use this file to discover all available pages before exploring further.

# JWT Authorization by Authorization code

> The authorization code is obtained by using an authorization server (COR) as an intermediary between the client and resource owner.



## OpenAPI

````yaml /api-reference/openapi.json post /oauth2/token
openapi: 3.1.0
info:
  title: COR API
  description: >-
    The COR API lets you integrate with projectcor.com applications using simple
    HTTP methods, in either XML or JSON formats, making this an ideal API for
    developing integrations with other softwares, external clients or mobile
    applications
  version: 1.0.0
servers:
  - url: https://api.projectcor.com/v1
    description: Production server
security:
  - bearerAuth: []
paths:
  /oauth2/token:
    post:
      tags:
        - Auth
      summary: JWT Authorization by Authorization code
      description: >-
        The authorization code is obtained by using an authorization server
        (COR) as an intermediary between the client and resource owner.
      parameters:
        - name: grant_type
          in: query
          required: true
          schema:
            type: string
            enum:
              - authorization_code
            default: authorization_code
        - name: code
          in: query
          required: true
          schema:
            type: string
          description: Authorization code obtained from consent screen
      responses:
        '200':
          description: Successfully authenticated
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuthResponse'
      security: []
components:
  schemas:
    AuthResponse:
      type: object
      properties:
        access_token:
          type: string
        token_type:
          type: string
        expires_in:
          type: integer
        refresh_token:
          type: string
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT

````