Sample code for 30+ languages & platforms
Unicode C

Refresh OAuth2 Access Token with Optional Params

See more OAuth2 Examples

Demonstrates how to refresh an OAuth2 access token with optional query params included in the HTTP request.

Chilkat Unicode C Downloads

Unicode C
#include <C_CkJsonObjectW.h>
#include <C_CkOAuth2W.h>
#include <C_CkStringBuilderW.h>

void ChilkatSample(void)
    {
    BOOL success;
    HCkJsonObjectW jsonToken;
    HCkOAuth2W oauth2;
    HCkStringBuilderW sbJson;

    success = FALSE;

    //  Here is a sampling of possible optional parameters that might
    //  be used by some OAuth2 providers.

    //  Optional Parameters
    //  
    //      "scope":
    //          Specifies the scope of the access request. If omitted, the authorization
    //          server may issue a token with the same scope as the original token.
    //          Example: "scope=read write"
    //  
    //      "redirect_uri":
    //          The redirect URI used in the original authorization request. Some
    //          servers may require this for validation.
    //          Example: "redirect_uri=https://example.com/callback"
    //  
    //      "resource":
    //          Indicates the target resource or audience for the token. This is used in
    //          some implementations (e.g., Microsoft Identity Platform).
    //          Example: "resource=https://api.example.com"
    //  
    //      "audience":
    //          Similar to "resource", this specifies the intended audience for the
    //          token (used in some OAuth2 implementations like Auth0).
    //          Example: "audience=https://api.example.com"
    //  
    //      "client_assertion" and "client_assertion_type":
    //          Used for client authentication using a signed JWT instead of a client
    //          secret.
    //          Example:client_assertion=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...        
    //          client_assertion_type=urn:ietf:params:oauth:client-assertion-type:jwt-bearer
    //  
    //      "token_type_hint":
    //          Provides a hint to the authorization server about the type of token
    //          being refreshed. This is rarely used but can be helpful in some cases.
    //          Example: "token_type_hint=refresh_token"
    //  
    //      "assertion":
    //          Used in some flows (e.g., SAML bearer assertion flow) to provide an
    //          assertion for token issuance.
    //          Example: "assertion=PHNhbWxwOl..."
    //  
    //      "requested_token_use":
    //          Specifies how the token will be used (e.g., "on_behalf_of" in the
    //          On-Behalf-Of flow used by Microsoft Identity Platform).
    //          Example: "requested_token_use=on_behalf_of"
    //  

    //  --------------------------------------------------------------------------------
    //  This example wll refresh the access token and includes the "audience"
    //  optional query parameter.
    //  
    //  

    //  Get the access token to be refreshed.
    jsonToken = CkJsonObjectW_Create();
    success = CkJsonObjectW_LoadFile(jsonToken,L"qa_data/tokens/myAccessToken.json");
    if (success != TRUE) {
        wprintf(L"Failed to load hmrc.json\n");
        CkJsonObjectW_Dispose(jsonToken);
        return;
    }

    oauth2 = CkOAuth2W_Create();

    CkOAuth2W_putTokenEndpoint(oauth2,L"https://api.example.com/oauth/token");

    //  Replace these with actual values.
    CkOAuth2W_putClientId(oauth2,L"CLIENT_ID");
    CkOAuth2W_putClientSecret(oauth2,L"CLIENT_SECRET");

    //  Add the optional refresh query param.
    //  Call AddRefreshQueryParam multiple times to add additional params.
    CkOAuth2W_AddRefreshQueryParam(oauth2,L"audience",L"https://api.example.com");

    //  Provide the existing refresh token from the JSON.
    CkOAuth2W_putRefreshToken(oauth2,CkJsonObjectW_stringOf(jsonToken,L"refresh_token"));

    //  Send the HTTP POST to refresh the access token..
    success = CkOAuth2W_RefreshAccessToken(oauth2);
    if (success != TRUE) {
        wprintf(L"%s\n",CkOAuth2W_lastErrorText(oauth2));
        CkJsonObjectW_Dispose(jsonToken);
        CkOAuth2W_Dispose(oauth2);
        return;
    }

    //  Load the access token response into the json object 
    CkJsonObjectW_Load(jsonToken,CkOAuth2W_accessTokenResponse(oauth2));

    //  Save the new JSON access token response to a file.
    //  The access + refresh tokens contained in this JSON will be needed for the next refresh.
    sbJson = CkStringBuilderW_Create();
    CkJsonObjectW_putEmitCompact(jsonToken,FALSE);
    CkJsonObjectW_EmitSb(jsonToken,sbJson);
    CkStringBuilderW_WriteFile(sbJson,L"qa_data/tokens/myAccessToken.json",L"utf-8",FALSE);

    wprintf(L"OAuth2 access token refreshed!\n");
    wprintf(L"New Access Token = %s\n",CkOAuth2W_accessToken(oauth2));


    CkJsonObjectW_Dispose(jsonToken);
    CkOAuth2W_Dispose(oauth2);
    CkStringBuilderW_Dispose(sbJson);

    }