> ## Documentation Index
> Fetch the complete documentation index at: https://api.fanvue.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Exchange a fan experience launch token

> Exchanges the opaque experience token an app's fan-experience surface received in its iframe URL for the resolved experience, the fan's identity, and the fan's entitlement to the experience.

    The token is bound to the app that owns the experience: a token minted for one app cannot be exchanged with another app's credentials (403).

    Returns 400 if the token is invalid or expired, and 404 if the experience no longer exists.

<Info>
  **Required scope**

  * `read:experience` — Exchange a fan's experience token for the resolved experience and the fan's identity, so an embedded fan-facing experience can render the right content.
</Info>


## OpenAPI

````yaml /openapi.json post /experiences/token/exchange
openapi: 3.1.0
info:
  title: Fanvue API
  version: '0.1'
servers: []
security: []
paths:
  /experiences/token/exchange:
    post:
      summary: Exchange a fan experience launch token
      description: >-
        Exchanges the opaque experience token an app's fan-experience surface
        received in its iframe URL for the resolved experience, the fan's
        identity, and the fan's entitlement to the experience.

            The token is bound to the app that owns the experience: a token minted for one app cannot be exchanged with another app's credentials (403).

            Returns 400 if the token is invalid or expired, and 404 if the experience no longer exists.
      operationId: exchangeExperienceToken
      parameters:
        - $ref: '#/components/parameters/ApiVersionHeader'
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                token:
                  type: string
                  minLength: 1
                  description: >-
                    The opaque experience launch token appended to the surface
                    iframe URL.
                  example: exp_2f1c…
              required:
                - token
      responses:
        '200':
          description: The resolved experience, fan identity, and entitlement
          content:
            application/json:
              schema:
                type: object
                properties:
                  experience:
                    type: object
                    properties:
                      uuid:
                        type: string
                        format: uuid
                      appUuid:
                        type: string
                        format: uuid
                      creatorUuid:
                        type: string
                        format: uuid
                      externalExperienceId:
                        type: string
                      title:
                        type: string
                      description:
                        type: string
                      accessMode:
                        type: string
                        enum:
                          - FREE
                          - SUBSCRIPTION
                          - PAID
                          - HIDDEN
                      hidden:
                        type: boolean
                    required:
                      - uuid
                      - appUuid
                      - creatorUuid
                      - externalExperienceId
                      - title
                      - description
                      - accessMode
                      - hidden
                  fanUuid:
                    type: string
                    format: uuid
                  entitlement:
                    type: object
                    properties:
                      isEntitled:
                        type: boolean
                      mode:
                        type: string
                        enum:
                          - FREE
                          - SUBSCRIPTION
                          - PAID
                          - HIDDEN
                      reason:
                        type: string
                    required:
                      - isEntitled
                      - mode
                      - reason
                required:
                  - experience
                  - fanUuid
                  - entitlement
              example:
                experience:
                  uuid: 00000000-0000-4000-8000-000000000010
                  appUuid: 00000000-0000-4000-8000-000000000001
                  creatorUuid: 00000000-0000-4000-8000-000000000002
                  externalExperienceId: ext-experience-123
                  title: Behind the scenes
                  description: An exclusive behind-the-scenes experience.
                  accessMode: SUBSCRIPTION
                  hidden: false
                fanUuid: 00000000-0000-4000-8000-000000000003
                entitlement:
                  isEntitled: true
                  mode: SUBSCRIPTION
                  reason: subscribed
        '400':
          description: Bad Request - API version not supported OR validation failed
          content:
            application/json:
              schema:
                oneOf:
                  - $ref: '#/components/schemas/UnsupportedVersionError'
                  - $ref: '#/components/schemas/ValidationError'
        '401':
          $ref: '#/components/responses/UnauthorizedResponse'
        '403':
          $ref: '#/components/responses/UnauthorizedResponse'
        '404':
          description: Experience not found
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
        '410':
          $ref: '#/components/responses/SunsetVersionResponse'
        '429':
          $ref: '#/components/responses/RateLimitResponse'
        '502':
          description: Failed to exchange the experience token with the upstream
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
        '503':
          description: Developer API upstream is not configured
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
      security:
        - BearerAuth:
            - read:experience
components:
  parameters:
    ApiVersionHeader:
      name: X-Fanvue-API-Version
      in: header
      required: true
      schema:
        type: string
        default: '2025-06-26'
        example: '2025-06-26'
      description: API version to use for the request
  schemas:
    UnsupportedVersionError:
      type: object
      properties:
        error:
          type: string
        message:
          type: string
      required:
        - error
        - message
      description: API version not supported
    ValidationError:
      type: object
      properties:
        errors:
          type: array
          items:
            type: string
      required:
        - errors
      description: Request validation failed
  responses:
    UnauthorizedResponse:
      description: Unauthorized Response
      content:
        application/json:
          schema:
            type: object
            properties:
              error:
                type: string
            required:
              - error
    SunsetVersionResponse:
      description: API version no longer supported (sunset)
      content:
        application/json:
          schema:
            type: object
            properties:
              error:
                type: string
              message:
                type: string
              nextVersion:
                type: string
            required:
              - error
              - message
    RateLimitResponse:
      description: Too many requests - rate limit exceeded
      headers:
        Retry-After:
          description: Number of seconds to wait before retrying the request
          schema:
            type: integer
        X-RateLimit-Limit:
          description: The maximum number of requests allowed in the current window
          schema:
            type: integer
        X-RateLimit-Remaining:
          description: The number of requests remaining in the current window
          schema:
            type: integer
        X-RateLimit-Reset:
          description: The Unix timestamp (seconds) when the rate limit window resets
          schema:
            type: integer
      content:
        application/json:
          schema:
            type: object
            properties:
              error:
                type: string
            required:
              - error
  securitySchemes:
    BearerAuth:
      type: oauth2
      description: >-
        OAuth 2.0 access token, presented as a JWT bearer token in the
        `Authorization` header. Obtain a token via the authorization-code flow;
        the scopes granted to the token determine which operations it may call.
      flows:
        authorizationCode:
          authorizationUrl: https://auth.fanvue.com/oauth2/auth
          tokenUrl: https://auth.fanvue.com/oauth2/token
          refreshUrl: https://auth.fanvue.com/oauth2/token
          scopes:
            read:self: >-
              Access your own user profile information, including basic account
              details and settings.
            read:chat: >-
              Read chat conversations, messages, and chat-related data. This
              includes viewing chat lists and message history.
            write:chat: >-
              Create new chats and send messages. This scope is required for any
              chat-related actions that modify data.
            read:experience: >-
              Exchange a fan's experience token for the resolved experience and
              the fan's identity, so an embedded fan-facing experience can
              render the right content.
            write:experience: >-
              Request that the creator publish or unpublish a fan-facing
              experience. The app mints a request token; the creator confirms
              and Fanvue performs the change.
            read:fan: Access fan-related data and information within the platform.
            read:post: Read posts, including post details, comments, likes, and tips.
            write:post: Create, edit, and manage posts and content on behalf of users.
            read:media: Access media files, images, videos, and other content assets.
            write:media: >-
              Upload, modify, and manage media files and content assets. Also
              required for vault folder management.
            read:creator: >-
              Access creator profiles, content, and creator-specific
              information.
            write:creator: Modify creator profiles, settings, and creator-specific data.
            read:insights: >-
              Access analytics, metrics, and insights data for performance
              tracking.
            read:tracking_links: >-
              Read tracking links and the users associated with them, including
              per-user tracking metadata.
            write:tracking_links: Create and delete tracking links.
            read:agency: Read agency information, including the agency's team members.
            write:agency: >-
              Manage agency team members and invites, including inviting new
              team members and creators.

````