OAuth API for Mobile - How to accomplish? Whitelist?

The auth code is not a token, it’s an auth code. Please read the authentication documentation: https://github.com/justintv/Twitch-API/blob/master/authentication.md#authorization-code-flow