Sample code for 30+ languages & platforms
Dart

POP3 Auto-Refresh Office365 Access Token

See more Office365 Examples

Demonstrates how to automatically recover from an expired OAuth2 access token when OAuth2 authentication fails in the POP3 protocol. If the server responds with "-ERR Authentication failure: unknown user name or bad password.", then we refresh the access token and retry.

Chilkat Dart Downloads

Dart
import 'package:chilkat/chilkat.dart';

void main() {
  // This example requires the Chilkat API to have been previously unlocked.
  // See Global Unlock Sample for sample code.

  final mailman = CkMailMan();

  mailman.mailHost = 'outlook.office365.com';
  mailman.mailPort = 995;
  mailman.popSsl = true;

  // Use your O365 email address here.
  mailman.popUsername = 'OFFICE365_EMAIL_ADDRESS';

  // When using OAuth2 authentication, leave the password empty.
  mailman.popPassword = '';

  // Load our previously obtained OAuth2 access token.
  final jsonToken = CkJsonObject();
  try {
    jsonToken.loadFile('qa_data/tokens/office365.json');
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  mailman.oAuth2AccessToken = jsonToken.stringOf('access_token');

  // Make the TLS connection to the outlook.office365.com POP3 server.
  try {
    mailman.pop3Connect();
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // Authenticate using XOAUTH2
  try {
    mailman.pop3Authenticate();
  } on ChilkatException catch (e) {
    // If we're still connected to the mail server, then it means the server sent a non-success response,
    // Such as:  -ERR Authentication failure: unknown user name or bad password.
    if (mailman.isPop3Connected) {

      // Refresh the OAuth2 access token, and if successful, save the new (refreshed) access token and try authenticating again.
      final oauth2 = CkOAuth2();

      // Use your actual Directory (tenant) ID instead of "112d7ed6-71bf-4eba-a866-738364321bfc"
      oauth2.tokenEndpoint = 'https://login.microsoftonline.com/112d7ed6-71bf-4eba-a866-738364321bfc/oauth2/v2.0/token';

      // Replace these with your Azure App Registration's actual values.
      oauth2.clientId = 'CLIENT_ID';
      oauth2.clientSecret = 'CLIENT_SECRET';

      // Get the "refresh_token"
      oauth2.refreshToken = jsonToken.stringOf('refresh_token');

      // Send the HTTP POST to refresh the access token..
      try {
        oauth2.refreshAccessToken();
      } on ChilkatException catch (e) {
        print(e.lastErrorText);
        return;
      }

      print('New access token: ${oauth2.accessToken}');
      print('New refresh token: ${oauth2.refreshToken}');

      // Update the JSON with the new tokens.
      jsonToken.updateString('access_token', oauth2.accessToken);
      jsonToken.updateString('refresh_token', oauth2.refreshToken);

      // Save the new JSON access token response to a file.
      final sbJson = CkStringBuilder();
      jsonToken.emitCompact = false;
      jsonToken.emitSb(sbJson);
      sbJson.writeFile('qa_data/tokens/office365.json', 'utf-8', false);

      print('New Access Token = ${oauth2.accessToken}');

      // Update the mailman with the new access token.
      mailman.oAuth2AccessToken = oauth2.accessToken;

      // Retry the authentication.
      try {
        mailman.pop3Authenticate();
      } on ChilkatException catch (e) {
        print(e.lastErrorText);
        return;
      }
    } else {
      print(e.lastErrorText);
      return;
    }
  }

  // Find out how many emails are on the server..
  final numEmails = mailman.checkMail();
  if (numEmails < 0) {
    print(mailman.lastErrorText);
    return;
  }

  // Examine the POP3 session log:
  print(mailman.pop3SessionLog);

  // The POP3 session log will look something like this:

  // **** Connected to outlook.office365.com:995
  // < +OK The Microsoft Exchange POP3 service is ready. [QwBIADIAUABSADEANgBDAEEAMAAwADEAMgAuAG4AYQBtAHAAcgBkADEANgAuAHAAcgBvAGQALgBvAHUAdABsAG8AbwBrAC4AYwBvAG0A]
  // > AUTH XOAUTH2
  // < + 
  // > <base64 string in XOAUTH2 format>
  // < -ERR Authentication failure: unknown user name or bad password.
  // > AUTH XOAUTH2
  // < + 
  // > <base64 string in XOAUTH2 format>
  // < +OK User successfully authenticated.
  // > STAT
  // < +OK 248 46637086

  // End the POP3 session and close the connection to the GMail server.
  try {
    mailman.pop3EndSession();
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  print('Finished.');
}