---
search:
  tags:
    - MCP
    - POST
seo:
  description: >-
    Exchange an authorization code for tokens. Reference for the POST
    /v1/mcp/oauth/callback endpoint in the Roboto REST API.
sidebar:
  label: Oauth callback
  badge: POST
title: Oauth callback
type: openapi-operation
---
Exchange an authorization code for tokens.

The server_id and org_id are recovered from the state token stored in the database,
so this endpoint doesn't need them in the URL — important because OAuth providers
(e.g., GitHub) only redirect with code + state.

### Access control
 - requires_org
 - Restricted tokens cannot call this endpoint

`POST /v1/mcp/oauth/callback`
