# Fetch an access token via the OAuth2 token-exchange flow

Operation ID: `connectors.zusGetAccessAndRefreshTokens`

Fetch an access token via the OAuth2 token-exchange flow. POSTs to ``{base}/auth/token`` exchanging the subject token. Returns the ``access_token`` string; authentication failures raise a typed :class:`ConnectorAuthError`.

## Public method

`getAccessAndRefreshTokens`

Signature: `connectors.zus.createClient(config).getAccessAndRefreshTokens(body)`

Return type: `Promise<ZusResponse>`

## Authentication

Classification: **AUTHENTICATED**

Schemes: `bearerAuth`

## Prerequisites

None documented.

## HTTP

`POST /connectors/zus/get-access-and-refresh-tokens`

## Path parameters

None.

## Query parameters

None.

## Body parameters

| Name | Type | Required | Format | Allowed values | Default | Nullable | Description |
|---|---|---:|---|---|---|---:|---|
| `body` | [`ZusGetAccessAndRefreshTokensRequest`](../models/ZusGetAccessAndRefreshTokensRequest.md) | Yes |  |  |  | No |  |

Request model: [`ZusGetAccessAndRefreshTokensRequest`](../models/ZusGetAccessAndRefreshTokensRequest.md)

## Request example

```json
{
  "account_id": "12345",
  "api_url_base": "example-api-url-base",
  "client_id": "12345",
  "client_secret": "example-client-secret",
  "mode": "sandbox",
  "subject_token": "example-access-token"
}
```

## Success responses

| Status | Shape | Content type | Description |
|---|---|---|---|
| `200` | [`ZusGetAccessAndRefreshTokensResponse`](../models/ZusGetAccessAndRefreshTokensResponse.md) | application/json | Successful response |

## Success response examples

### 200

```json
"example-get-access-and-refresh-tokens"
```

## Common errors

| Status | Shape | Content type | Description |
|---|---|---|---|
| `400` | [`StandardErrorResponse`](../models/StandardErrorResponse.md) | application/json | Connector validation rejected the payload, or a required field was missing or of the wrong type. |
| `401` | [`StandardErrorResponse`](../models/StandardErrorResponse.md) | application/json | The HealthCloud bearer token is missing or invalid, or the vendor rejected the supplied connector credentials. |
| `500` | [`StandardErrorResponse`](../models/StandardErrorResponse.md) | application/json | The connector failed unexpectedly. |
| `502` | [`StandardErrorResponse`](../models/StandardErrorResponse.md) | application/json | The vendor returned an application or transport-level failure. |
| `504` | [`StandardErrorResponse`](../models/StandardErrorResponse.md) | application/json | The vendor did not respond within the connector timeout. |

## Error examples

### 400 — Invalid request

```json
{
  "error": "Invalid request"
}
```

### 401 — Authorization required

```json
{
  "error": "Authorization required"
}
```

### 500 — Internal error

```json
{
  "error": "Internal error"
}
```

### 502 — Upstream vendor error

```json
{
  "error": "Upstream vendor error"
}
```

### 504 — Upstream timeout

```json
{
  "error": "Upstream timeout"
}
```

## NodeJS / TypeScript implementation

```ts
import { HCSDK } from "@healthcloudai/hc-sdk";
import type { ZusEmptyRequest } from "@healthcloudai/hc-sdk";
```

```ts
const body = {
  "account_id": "12345",
  "api_url_base": "example-api-url-base",
  "client_id": "12345",
  "client_secret": "example-client-secret",
  "mode": "sandbox",
  "subject_token": "example-access-token"
};

const result = await connectors.zus.createClient(config).getAccessAndRefreshTokens(body);
```

## cURL

```bash
curl -X POST \
  -H 'Authorization: Bearer <ACCESS_TOKEN>' \
  -H 'Content-Type: application/json' \
  -d '{"account_id":"12345","api_url_base":"example-api-url-base","client_id":"12345","client_secret":"example-client-secret","mode":"sandbox","subject_token":"example-access-token"}' \
  'https://dev-api-connectors.health.cloud/connectors/zus/get-access-and-refresh-tokens'
```

## Notes

None.

## Prepared Test Console scenario

No canonical scenario is currently associated.

## Real response

No approved real integration response is currently published. Unapproved candidates are never rendered as examples.
