Sample code for 30+ languages & platforms
Delphi ActiveX

RSAP Union API - Get OAuth2 Access Token

See more _Miscellaneous_ Examples

Demonstrates how to get an OAuth2 access token for the RSAP Union API. Note: This uses the client credentials flow, which does NOT require an interactive engagement using a browser.

Chilkat Delphi ActiveX Downloads

Delphi ActiveX
uses
    Winapi.Windows, Winapi.Messages, System.SysUtils, System.Variants, System.Classes, Vcl.Graphics,
    Vcl.Controls, Vcl.Forms, Vcl.Dialogs, Vcl.StdCtrls, Chilkat_TLB;

...

procedure TForm1.Button1Click(Sender: TObject);
var
success: Integer;
http: TChilkatHttp;
json: TChilkatJsonObject;
cert: TChilkatCert;
privKey: TPrivateKey;
resp: TChilkatHttpResponse;
sbResponseBody: TChilkatStringBuilder;
jResp: TChilkatJsonObject;
respStatusCode: Integer;

begin
success := 0;

// This example assumes the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

http := TChilkatHttp.Create(Self);

// The following JSON is sent in the request body.

// {
//   "grant_type": "client_credentials",
//   "client_id": 1234,
//   "client_secret": "23456abcde"
// }

json := TChilkatJsonObject.Create(Self);
json.UpdateString('grant_type','client_credentials');
json.UpdateInt('client_id',1234);
json.UpdateString('client_secret','23456abcde');

http.SetRequestHeader('Content-type','application/json');

// Add the client certificate TLS authentication.
cert := TChilkatCert.Create(Self);
success := cert.LoadFromFile('qa_data/certs_and_keys/union_client_certificate.crt');
if (success = 0) then
  begin
    Memo1.Lines.Add(cert.LastErrorText);
    Exit;
  end;

privKey := TPrivateKey.Create(Self);
success := privKey.LoadAnyFormatFile('qa_data/certs_and_keys/union_client_certificate.nopass.key','');
if (success = 0) then
  begin
    Memo1.Lines.Add(privKey.LastErrorText);
    Exit;
  end;

// Associate the private key with the cert.
// This will fail if the private key is not actually the correct one that corresponds to the public key stored within the cert.
success := cert.SetPrivateKey(privKey.ControlInterface);
if (success = 0) then
  begin
    Memo1.Lines.Add(cert.LastErrorText);
    Exit;
  end;

// Tell HTTP to use the cert for client TLS certificate authentication.
success := http.SetSslClientCert(cert.ControlInterface);
if (success = 0) then
  begin
    Memo1.Lines.Add(http.LastErrorText);
    Exit;
  end;

resp := TChilkatHttpResponse.Create(Self);
success := http.HttpJson('POST','https://api-test.rsap.ca/oauth/token',json.ControlInterface,'application/json',resp.ControlInterface);
if (success = 0) then
  begin
    Memo1.Lines.Add(http.LastErrorText);
    Exit;
  end;

sbResponseBody := TChilkatStringBuilder.Create(Self);
resp.GetBodySb(sbResponseBody.ControlInterface);
jResp := TChilkatJsonObject.Create(Self);
jResp.LoadSb(sbResponseBody.ControlInterface);
jResp.EmitCompact := 0;

Memo1.Lines.Add('Response Body:');
Memo1.Lines.Add(jResp.Emit());

respStatusCode := resp.StatusCode;
Memo1.Lines.Add('Response Status Code = ' + IntToStr(respStatusCode));
if (respStatusCode >= 400) then
  begin
    Memo1.Lines.Add('Response Header:');
    Memo1.Lines.Add(resp.Header);
    Memo1.Lines.Add('Failed.');
    Exit;
  end;

// Sample JSON response:
// (Sample code for parsing the JSON response is shown below)

// {
//   "token_type": "Bearer",
//   "expires_in": 3600,
//   "access_token": "eyJ0eXAi...LnE"
// }

// This token expires in 1 hour.  Your application could re-use the same token for up to an hour,
// or it can simply get a new access token before each request (if you're not doing too many requests).
success := jResp.WriteFile('qa_data/tokens/rsapToken.json');
end;