pub async fn exchange_code(
api_base: &Url,
code: &str,
expected_owner: &str,
) -> Result<AppCredentials>Expand description
Exchange the redirect’s code for the App’s credentials
(POST /app-manifests/{code}/conversions). The code is single-use and
expires after an hour.
expected_owner is the org (or user) the admin set out to register the
App under — the one passed to registration_url. An App registered
anywhere else is refused: its key would act for the wrong account.