Xbase++
Xbase++
RSAP Union API - Get OAuth2 Access Token
See more _Miscellaneous_ Examples
Demonstrates how to get an OAuth2 access token for the RSAP Union API. Note: This uses the client credentials flow, which does NOT require an interactive engagement using a browser.Chilkat Xbase++ Downloads
LOCAL nSuccess
LOCAL oHttp
LOCAL oJson
LOCAL oCert
LOCAL oPrivKey
LOCAL oResp
LOCAL oSbResponseBody
LOCAL oJResp
LOCAL nRespStatusCode
nSuccess := 0
// This example assumes the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
oHttp := CreateObject("Chilkat.Http")
// The following JSON is sent in the request body.
// {
// "grant_type": "client_credentials",
// "client_id": 1234,
// "client_secret": "23456abcde"
// }
oJson := CreateObject("Chilkat.JsonObject")
oJson:UpdateString("grant_type", "client_credentials")
oJson:UpdateInt("client_id", 1234)
oJson:UpdateString("client_secret", "23456abcde")
oHttp:SetRequestHeader("Content-type", "application/json")
// Add the client certificate TLS authentication.
oCert := CreateObject("Chilkat.Cert")
nSuccess := oCert:LoadFromFile("qa_data/certs_and_keys/union_client_certificate.crt")
IF (nSuccess == 0)
? oCert:LastErrorText
oHttp:destroy()
oJson:destroy()
oCert:destroy()
RETURN
ENDIF
oPrivKey := CreateObject("Chilkat.PrivateKey")
nSuccess := oPrivKey:LoadAnyFormatFile("qa_data/certs_and_keys/union_client_certificate.nopass.key", "")
IF (nSuccess == 0)
? oPrivKey:LastErrorText
oHttp:destroy()
oJson:destroy()
oCert:destroy()
oPrivKey:destroy()
RETURN
ENDIF
// Associate the private key with the cert.
// This will fail if the private key is not actually the correct one that corresponds to the public key stored within the cert.
nSuccess := oCert:SetPrivateKey(oPrivKey)
IF (nSuccess == 0)
? oCert:LastErrorText
oHttp:destroy()
oJson:destroy()
oCert:destroy()
oPrivKey:destroy()
RETURN
ENDIF
// Tell HTTP to use the cert for client TLS certificate authentication.
nSuccess := oHttp:SetSslClientCert(oCert)
IF (nSuccess == 0)
? oHttp:LastErrorText
oHttp:destroy()
oJson:destroy()
oCert:destroy()
oPrivKey:destroy()
RETURN
ENDIF
oResp := CreateObject("Chilkat.HttpResponse")
nSuccess := oHttp:HttpJson("POST", "https://api-test.rsap.ca/oauth/token", oJson, "application/json", oResp)
IF (nSuccess == 0)
? oHttp:LastErrorText
oHttp:destroy()
oJson:destroy()
oCert:destroy()
oPrivKey:destroy()
oResp:destroy()
RETURN
ENDIF
oSbResponseBody := CreateObject("Chilkat.StringBuilder")
oResp:GetBodySb(oSbResponseBody)
oJResp := CreateObject("Chilkat.JsonObject")
oJResp:LoadSb(oSbResponseBody)
oJResp:EmitCompact := 0
? "Response Body:"
? oJResp:Emit()
nRespStatusCode := oResp:StatusCode
? "Response Status Code = " + Str(nRespStatusCode)
IF (nRespStatusCode >= 400)
? "Response Header:"
? oResp:Header
? "Failed."
oHttp:destroy()
oJson:destroy()
oCert:destroy()
oPrivKey:destroy()
oResp:destroy()
oSbResponseBody:destroy()
oJResp:destroy()
RETURN
ENDIF
// Sample JSON response:
// (Sample code for parsing the JSON response is shown below)
// {
// "token_type": "Bearer",
// "expires_in": 3600,
// "access_token": "eyJ0eXAi...LnE"
// }
// This token expires in 1 hour. Your application could re-use the same token for up to an hour,
// or it can simply get a new access token before each request (if you're not doing too many requests).
nSuccess := oJResp:WriteFile("qa_data/tokens/rsapToken.json")
oHttp:destroy()
oJson:destroy()
oCert:destroy()
oPrivKey:destroy()
oResp:destroy()
oSbResponseBody:destroy()
oJResp:destroy()