# Exchange an app code for a key (/docs/api/access/auth_keys_exchange)

Final step of Sign in with GridRouter: exchange the one-time code and its PKCE code_verifier for a user-controlled key with call/run scopes and any credit limit the user set.

`POST /v1/auth/keys`

```json
{
  "operationId": "auth_keys_exchange",
  "summary": "Exchange an app code for a key",
  "description": "Final step of Sign in with GridRouter: exchange the one-time code and its PKCE code_verifier for a user-controlled key with call/run scopes and any credit limit the user set.",
  "tags": [
    "auth"
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "code": {
              "type": "string",
              "pattern": "^grc_[A-Za-z0-9_-]{4,120}\\.[A-Za-z0-9_-]{32,64}$"
            },
            "code_verifier": {
              "type": "string",
              "minLength": 43,
              "maxLength": 128,
              "pattern": "^[A-Za-z0-9._~-]+$"
            },
            "code_challenge_method": {
              "type": "string",
              "enum": [
                "S256"
              ],
              "default": "S256"
            }
          },
          "required": [
            "code",
            "code_verifier"
          ]
        }
      }
    }
  },
  "responses": {
    "200": {
      "description": "OK",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "object": {
                "type": "string",
                "enum": [
                  "auth_key"
                ]
              },
              "key": {
                "type": "string"
              },
              "key_id": {
                "type": "string"
              },
              "scopes": {
                "type": "array",
                "items": {
                  "type": "string",
                  "enum": [
                    "*",
                    "call",
                    "run",
                    "jobs",
                    "lists",
                    "catalog:read",
                    "balance:read",
                    "logs:read",
                    "billing:write",
                    "keys:write",
                    "agents:write",
                    "credentials:write",
                    "presets:write",
                    "pipelines:read",
                    "pipelines:write",
                    "pipelines:run",
                    "cache:write"
                  ]
                }
              },
              "limit_micro": {
                "type": [
                  "integer",
                  "null"
                ],
                "minimum": 0
              },
              "limit_reset": {
                "type": "string",
                "enum": [
                  "day",
                  "week",
                  "month",
                  "never"
                ]
              },
              "app_name": {
                "type": [
                  "string",
                  "null"
                ]
              },
              "expires_at": {
                "type": [
                  "string",
                  "null"
                ],
                "format": "date-time"
              }
            },
            "required": [
              "object",
              "key",
              "key_id",
              "scopes",
              "limit_micro",
              "limit_reset",
              "app_name",
              "expires_at"
            ]
          }
        }
      }
    },
    "default": {
      "description": "Error",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "error": {
                "type": "object",
                "properties": {
                  "code": {
                    "type": "string",
                    "enum": [
                      "invalid_request",
                      "unauthorized",
                      "insufficient_balance",
                      "max_cost_exceeded",
                      "scope_denied",
                      "budget_blocked",
                      "not_found",
                      "idempotency_mismatch",
                      "invalid_meta",
                      "rate_limited",
                      "upstream_error",
                      "response_buffer_limit",
                      "provider_capacity_unavailable",
                      "grid_saturated",
                      "upstream_timeout",
                      "conflict",
                      "internal_error",
                      "account_frozen",
                      "strict_filters",
                      "plan_limit_reached",
                      "validation_failed",
                      "deadline_exceeded",
                      "cancelled"
                    ]
                  },
                  "message": {
                    "type": "string"
                  },
                  "request_id": {
                    "type": "string"
                  },
                  "call_id": {
                    "type": "string"
                  },
                  "retry_after_ms": {
                    "type": "integer",
                    "minimum": 0
                  },
                  "details": {
                    "type": "object",
                    "additionalProperties": {}
                  }
                },
                "required": [
                  "code",
                  "message"
                ]
              }
            },
            "required": [
              "error"
            ]
          }
        }
      }
    }
  }
}
```
