Sample code for 30+ languages & platforms
Delphi DLL

Hotmail Refresh Access Token (also for Live.com, Outlook.com)

See more OAuth2 Examples

An OAuth2 access token is typically valid for 1 hour. Interaction with the Hotmail account owner via a browser is only needed for getting the initial access token. Once you have it, it can be continually refreshed without user interaction for a long time.

See: How Long can an OAuth2 Access Token be Refreshed?

Chilkat Delphi DLL Downloads

Delphi DLL
uses
    Winapi.Windows, Winapi.Messages, System.SysUtils, System.Variants, System.Classes, Vcl.Graphics,
    Vcl.Controls, Vcl.Forms, Vcl.Dialogs, Vcl.StdCtrls, OAuth2, StringBuilder, JsonObject;

...

procedure TForm1.Button1Click(Sender: TObject);
var
success: Boolean;
jsonToken: HCkJsonObject;
oauth2: HCkOAuth2;
sbJson: HCkStringBuilder;

begin
success := False;

// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

// It is assumed we previously obtained an OAuth2 access token.

// Note: Refreshing an access token does not require user-interaction.  
// Only the act of getting the initial access token requires interactive authorization from the Hotmail account owner 
// (i.e. a browser is displayed and the Hotmail account owner authorizes access by the app).

// Once you have the initial access token, it can be refreshed for a long time.
// A typical strategy is to write your application to automatically refresh the access token 
// when authentication fails, and then retry the operation with the new access token.

jsonToken := CkJsonObject_Create();
success := CkJsonObject_LoadFile(jsonToken,'qa_data/tokens/hotmail.json');
if (success <> True) then
  begin
    Memo1.Lines.Add('Failed to load office365.json');
    Exit;
  end;

// The access token JSON looks like this:

// {
//   "token_type": "Bearer",
//   "scope": "https://outlook.office.com/SMTP.Send https://outlook.office.com/IMAP.AccessAsUser.All https://outlook.office.com/POP.AccessAsUser.All",
//   "expires_in": 3600,
//   "ext_expires_in": 3600,
//   "access_token": "EwBoA+ ... 7pOYcWr5pFwQgI=",
//   "refresh_token": "M.C546_BL2.0.U.-CkW ... g5CKSlDBQ$$",
//   "id_token": "eyJ0e ... 2iiu5iqBK9n7s3A"
// }

oauth2 := CkOAuth2_Create();

// See Microsoft OAuth2 Authorization Endpoint
CkOAuth2_putTokenEndpoint(oauth2,'https://login.microsoftonline.com/common/oauth2/v2.0/token');

// Replace this with your actual App Registration's Application (client) ID.
CkOAuth2_putClientId(oauth2,'CLIENT_ID');

// Get the "refresh_token"
CkOAuth2_putRefreshToken(oauth2,CkJsonObject__stringOf(jsonToken,'refresh_token'));

// Send the HTTP POST to refresh the access token..
success := CkOAuth2_RefreshAccessToken(oauth2);
if (success <> True) then
  begin
    Memo1.Lines.Add(CkOAuth2__lastErrorText(oauth2));
    Exit;
  end;
Memo1.Lines.Add(CkOAuth2__lastErrorText(oauth2));

Memo1.Lines.Add('New access token: ' + CkOAuth2__accessToken(oauth2));
Memo1.Lines.Add('New refresh token: ' + CkOAuth2__refreshToken(oauth2));

// Update the JSON with the new tokens.
CkJsonObject_UpdateString(jsonToken,'access_token',CkOAuth2__accessToken(oauth2));
CkJsonObject_UpdateString(jsonToken,'refresh_token',CkOAuth2__refreshToken(oauth2));

// Save the new JSON access token response to a file.
sbJson := CkStringBuilder_Create();
CkJsonObject_putEmitCompact(jsonToken,False);
CkJsonObject_EmitSb(jsonToken,sbJson);
CkStringBuilder_WriteFile(sbJson,'qa_data/tokens/hotmail.json','utf-8',False);

Memo1.Lines.Add('OAuth2 authorization granted!');
Memo1.Lines.Add('New Access Token = ' + CkOAuth2__accessToken(oauth2));

CkJsonObject_Dispose(jsonToken);
CkOAuth2_Dispose(oauth2);
CkStringBuilder_Dispose(sbJson);

end;