Since the exchange uses your client secret key, to keep the integrity of the key, you should make that request server-side. This request is sent to the token endpoint of the Spotify accounts service: The body of this POST request must contain the following parameters encoded as application/x-www-form-urlencoded as defined in the OAuth 2.0 specification. Visit the following URL after replacing $CLIENT_ID, $SCOPE, and $REDIRECT_URI with the information you noted in Step 1. For example: JVM, Android, JS, Native; Android information; Documentation; Need help, have a question, or want to contribute? Only endpoints that do not access user information can be accessed. … Authorization Flow Clicking "Login" makes a request to the /login function that generates and returns a Spotify authorization URL See available scopes. AuthorizationCodeFlow authorizationCodeFlow = new AuthorizationCodeFlow. 