Sample code for 30+ languages & platforms
Xbase++

Automatically Refresh Token for 401 Unauthorized

See more Google Calendar Examples

Demonstrates how to automatically refresh an access token (without user interaction) when the token expires and a 401 Unauthorized response is received.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL cTokenFilePath
LOCAL oJsonToken
LOCAL oHttp
LOCAL cJsonResponse
LOCAL oOauth2
LOCAL oSbJson

nSuccess := 0

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

cTokenFilePath := "qa_data/tokens/googleCalendar.json"

//  Get our current access token.
oJsonToken := CreateObject("Chilkat.JsonObject")
nSuccess := oJsonToken:LoadFile(cTokenFilePath)
IF (oJsonToken:HasMember("access_token") == 0)
    ? "No access token found."
    oJsonToken:destroy()
    RETURN
ENDIF

oHttp := CreateObject("Chilkat.Http")
oHttp:AuthToken := oJsonToken:StringOf("access_token")

cJsonResponse := oHttp:QuickGetStr("https://www.googleapis.com/calendar/v3/users/me/calendarList")
IF (oHttp:LastMethodSuccess != 1)

    IF (oHttp:LastStatus != 401)
        ? oHttp:LastErrorText
        ? "----"
        ? oHttp:LastResponseBody
        oJsonToken:destroy()
        oHttp:destroy()
        RETURN
    ENDIF

    //  The access token must've expired. 
    //  Refresh the access token and then retry the request.
    oOauth2 := CreateObject("Chilkat.OAuth2")

    oOauth2:TokenEndpoint := "https://www.googleapis.com/oauth2/v4/token"

    //  Replace these with actual values.
    oOauth2:ClientId := "GOOGLE-CLIENT-ID"
    oOauth2:ClientSecret := "GOOGLE-CLIENT-SECRET"

    //  Get the "refresh_token"
    oOauth2:RefreshToken := oJsonToken:StringOf("refresh_token")

    //  Send the HTTP POST to refresh the access token..
    nSuccess := oOauth2:RefreshAccessToken()
    IF (nSuccess != 1)
        ? oOauth2:LastErrorText
        oJsonToken:destroy()
        oHttp:destroy()
        oOauth2:destroy()
        RETURN
    ENDIF

    //  The response contains a new access token, but we must keep
    //  our existing refresh token for when we need to refresh again in the future.
    oJsonToken:UpdateString("access_token", oOauth2:AccessToken)

    //  Save the new JSON access token response to a file.
    oSbJson := CreateObject("Chilkat.StringBuilder")
    oJsonToken:EmitCompact := 0
    oJsonToken:EmitSb(oSbJson)
    oSbJson:WriteFile(cTokenFilePath, "utf-8", 0)

    ? "OAuth2 authorization granted!"
    ? "New Access Token = " + oOauth2:AccessToken

    //  re-try the original request.
    oHttp:AuthToken := oOauth2:AccessToken
    cJsonResponse := oHttp:QuickGetStr("https://www.googleapis.com/calendar/v3/users/me/calendarList")
    IF (oHttp:LastMethodSuccess != 1)
        ? oHttp:LastErrorText
        oJsonToken:destroy()
        oHttp:destroy()
        oOauth2:destroy()
        oSbJson:destroy()
        RETURN
    ENDIF

ENDIF

? cJsonResponse
? "-----------------------------"

oJsonToken:destroy()
oHttp:destroy()
oOauth2:destroy()
oSbJson:destroy()