## TL;DR

Looks like Box requires a correct Content-Type: application/x-www-form-urlencoded request header in addition to properly URL encoding the parameters. The same seems to apply to refresh and revoke requests.

## The error

```text
Invalid grant_type parameter or parameter missing
```

## Fix

1. Looks like Box requires a correct Content-Type: application/x-www-form-urlencoded request header in addition to properly URL encoding the parameters.
   Expected: You get the expected result; the problem is gone.
2. The same seems to apply to refresh and revoke requests.
   Expected: You get the expected result; the problem is gone.
3. Also, per RFC 6749, the redirect_uri is only REQUIRED, if the "redirect_uri" parameter was included in the authorization request as described in Section 4.1.1, and their values MUST be identical.
   Expected: You get the expected result; the problem is gone.
4. Re-run the original operation and confirm the error is gone.
   Expected: no error, normal output.

## When to use

- You hit this exact error with Box oauth2.
- The symptom matches: Invalid grant_type parameter or parameter missing.

## When NOT to use

- A different error message from Box oauth2; the cause here is specific to this error.
- Unrelated Box oauth2 issues (different feature, different failure).
- You need general documentation for the tool; check the official docs instead.

## Compatibility

Reported against Box oauth2 (mentions 4.1.1).

## Variant phrasings

### Invalid grant_type parameter or parameter missing

## Why it happens

Stack Overflow question (score 11, has accepted answer): Exchanging the authorization code for tokens at the Box token endpoint keeps returning 400 "Invalid grant_type parameter or parameter missing", even though grant_type, code, client_id and client_secret are all being posted as form fields.

## Edge cases

- If your error message differs even slightly, this is probably a different issue; search the exact text.
- Behavior can change between releases; the linked source reflects the versions above.
- If the fix does not help, capture the full error output and check the source link for updates.