> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hexclave.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Exchange an external authentication token

> Verifies a configured external provider session and returns a short-lived Hexclave access token.



## OpenAPI

````yaml /openapi/server.json post /auth/external/token
openapi: 3.1.0
info:
  title: Hexclave REST API
  version: 1.0.0
  description: >-
    The Hexclave REST API. All request headers are documented as canonical
    `X-Hexclave-*`; the equivalent `X-Stack-*` aliases are accepted on every
    endpoint for backwards compatibility. Response headers
    `X-Hexclave-actual-status`, `X-Hexclave-known-error`, and
    `X-Hexclave-request-id` are emitted alongside their legacy `X-Stack-*`
    equivalents.
servers:
  - url: https://api.hexclave.com/api/v1
    description: Hexclave REST API
security: []
paths:
  /auth/external/token:
    post:
      tags:
        - External authentication
      summary: Exchange an external authentication token
      description: >-
        Verifies a configured external provider session and returns a
        short-lived Hexclave access token.
      parameters: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                provider_id:
                  type: string
                  enum:
                    - clerk-integration
                    - better-auth-integration
                    - workos-integration
                  example: clerk-integration
                  description: >-
                    The external authentication integration that issued the
                    token.
                token:
                  type: string
                  example: <external-provider-jwt>
                  description: >-
                    The provider's signed session token (a JWT). It must contain
                    sub, sid and exp claims.
              required:
                - provider_id
                - token
              example:
                provider_id: clerk-integration
                token: <external-provider-jwt>
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
                properties:
                  access_token:
                    type: string
                  session_id:
                    type: string
                  user_id:
                    type: string
                  is_new_user:
                    type: boolean
                required:
                  - access_token
                  - session_id
                  - user_id
                  - is_new_user

````