{ "$schema": "https://json-schema.org/draft/2020-12/schema", "$id": "https://raw.githubusercontent.com/api-evangelist/gitlab/main/json-schema/gitlab-token-request-schema.json", "title": "TokenRequest", "x-generated": "2026-10-04", "x-method": "derived", "x-generator": "derive-json-schema.py", "x-source": "openapi/gitlab-tokens-api-openapi.yml#/components/schemas/TokenRequest", "type": "object", "required": [ "grant_type", "client_id" ], "properties": { "grant_type": { "type": "string", "enum": [ "authorization_code", "refresh_token", "device_code", "password" ], "description": "The grant type for the token request." }, "client_id": { "type": "string", "description": "The application ID registered in GitLab." }, "client_secret": { "type": "string", "description": "The application secret. Required for confidential clients using authorization_code or refresh_token grant types." }, "code": { "type": "string", "description": "The authorization code received from the authorize endpoint." }, "redirect_uri": { "type": "string", "format": "uri", "description": "The redirect URI used in the original authorization request." }, "code_verifier": { "type": "string", "description": "The PKCE code verifier corresponding to the code_challenge." }, "refresh_token": { "type": "string", "description": "The refresh token to exchange for a new access token." }, "device_code": { "type": "string", "description": "The device code from the device authorization response." }, "username": { "type": "string", "description": "Resource owner username. Only for password grant type." }, "password": { "type": "string", "description": "Resource owner password. Only for password grant type." } } }