The provider descriptor naming the token endpoint and the sanitize label.
The URL-encoded grant fields (grant_type, client_id, and the code, verifier, or refresh token as applicable).
Optionalsignal: AbortSignal
Optional AbortSignal to cancel the grant while it is in flight; takes precedence over options.signal when both are given.
Optionaloptions: RequestOptions
Optional transport settings for the grant call; timeout defaults to TOKEN_REQUEST_TIMEOUT_MS (10 seconds) and retry defaults to disabled. Pass an explicit retry policy to opt back in.
The parsed token response on success.
Runs one form-encoded OAuth token grant through the shared transport.
Both providers send authorization-code and refresh grants as
application/x-www-form-urlencodedfields to the descriptor's token endpoint. Both use one policy: a short timeout, retries off by default because grant credentials are single-use (a retried authorization code or PKCE verifier is consumed server-side, so the retry fails again while doubling token-endpoint traffic; a caller opts back in with an explicitretrypolicy), andexposeRawAxiosErrorforced off because the request body carriesclient_secret, authorizationcode, andrefresh_tokenvalues. Failures are rethrown throughsanitizeTokenErrorunder the descriptor'serrorLabel, so error payloads never leak credentials.