Sample code for 30+ languages & platforms
Objective-C Requires Chilkat v11.0.0+

Office365 OAuth2 Resource Owner Password Credentials Grant for SMTP, IMAP, POP

Demonstrates how to get an OAuth2 access token for use with Office 365 in the SMTP, IMAP, and POP3 protocols using the resource owner password credentials grant.

This is a way of getting an OAuth2 access token for the O365 account you own, WITHOUT needing to grant access interactively via a browser.

Chilkat Objective-C Downloads

Objective-C
#import <CkoHttp.h>
#import <CkoHttpRequest.h>
#import <CkoHttpResponse.h>
#import <CkoFileAccess.h>

BOOL success = NO;

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

//  Get an OAuth2 access token by sending a POST like this:

//  	POST {tenant}/oauth2/v2.0/token
//  	Host: login.microsoftonline.com
//  	Content-Type: application/x-www-form-urlencoded
//  
//  	client_id=6731de76-14a6-49ae-97bc-6eba6914391e
//  	&client_secret=*****************
//  	&scope=user.read%20openid%20profile%20offline_access
//  	&username=MyUsername@myTenant.com
//  	&password=SuperS3cret
//  	&grant_type=password

CkoHttp *http = [[CkoHttp alloc] init];

CkoHttpRequest *req = [[CkoHttpRequest alloc] init];
req.HttpVerb = @"POST";
req.ContentType = @"application/x-www-form-urlencoded";

//  Use the application ID for the client_id.
//  (In Azure App Registrations, use the Application (client) ID)
[req AddParam: @"client_id" value: @"CLIENT_ID"];
[req AddParam: @"client_secret" value: @"CLIENT_SECRET"];

[req AddParam: @"scope" value: @"openid profile offline_access https://outlook.office365.com/SMTP.Send https://outlook.office365.com/POP.AccessAsUser.All https://outlook.office365.com/IMAP.AccessAsUser.All"];
[req AddParam: @"username" value: @"my_email_address"];
[req AddParam: @"password" value: @"my_email_password"];
[req AddParam: @"grant_type" value: @"password"];

//  Replace "{tenant}" with your tenant ID, such as "112d7ed6-71bf-4eba-a866-738364321bfc".req.HttpVerb = "POST";
CkoHttpResponse *resp = [[CkoHttpResponse alloc] init];
success = [http HttpReq: @"https://login.microsoftonline.com/{tenant}/oauth2/v2.0/token" request: req response: resp];
if (success == NO) {
    NSLog(@"%@",http.LastErrorText);
    return;
}

int statusCode = [resp.StatusCode intValue];
NSLog(@"%@%d",@"response status code: ",statusCode);
NSLog(@"%@",@"response body:");
NSLog(@"%@",resp.BodyStr);

//  The successful JSON response looks like this:

//  {
//    "token_type": "Bearer",
//    "scope": "https://outlook.office365.com/IMAP.AccessAsUser.All https://outlook.office365.com/POP.AccessAsUser.All https://outlook.office365.com/SMTP.Send",
//    "expires_in": 3599,
//    "ext_expires_in": 3599,
//    "access_token": "eyJ0eX ... 62Nyw",
//    "refresh_token": "0.AAAA1n4t ... tNxyA",
//    "id_token": "eyJ0eXA ... qdIGyOYw"
//  }

//  Save the JSON to a file for future requests.
if (statusCode == 200) {
    CkoFileAccess *fac = [[CkoFileAccess alloc] init];
    [fac WriteEntireTextFile: @"qa_data/tokens/office365.json" fileData: resp.BodyStr charset: @"utf-8" includePreamble: NO];
}