Sample code for 30+ languages & platforms
Tcl

IMAP Auto-Refresh Office365 Access Token

See more Office365 Examples

Demonstrates how to automatically recover from an expired access token when OAuth2 authentication fails in the IMAP protocol. If the server responds with "NO AUTHENTICATE failed.", then we refresh the access token and retry.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

# An Office365 OAuth2 access token must first be obtained prior
# to running this code.

# Getting the OAuth2 access token for the 1st time requires the O365 account owner's 
# interactive authorizaition via a web browser.  Afterwards, the access token
# can be repeatedly refreshed automatically.

# See the following examples for getting and refreshing an OAuth2 access token

# Get Office365 SMTP/IMAP/POP3 OAuth2 Access Token
# Refresh Office365 SMTP/IMAP/POP3 OAuth2 Access Token

# First get our previously obtained OAuth2 access token.
set jsonToken [new_CkJsonObject]

set success [CkJsonObject_LoadFile $jsonToken "qa_data/tokens/office365.json"]
if {$success == 0} then {
    puts "Failed to open the office365 OAuth JSON file."
    delete_CkJsonObject $jsonToken
    exit
}

set imap [new_CkImap]

CkImap_put_Ssl $imap 1
CkImap_put_Port $imap 993

# Connect to the Office365 IMAP server.
set success [CkImap_Connect $imap "outlook.office365.com"]
if {$success != 1} then {
    puts [CkImap_lastErrorText $imap]
    delete_CkJsonObject $jsonToken
    delete_CkImap $imap
    exit
}

# Use OAuth2 authentication.
CkImap_put_AuthMethod $imap "XOAUTH2"

# Login using our username (i.e. email address) and the access token for the password.
set success [CkImap_Login $imap "OFFICE365_EMAIL_ADDRESS" [CkJsonObject_stringOf $jsonToken "access_token"]]
if {$success != 1} then {
    set loginLastErrorText [CkImap_lastErrorText $imap]

    # If we're still connected to the mail server, then it means the server sent a non-success response,
    # Such as:  NO AUTHENTICATE failed.
    if {[CkImap_IsConnected $imap] == 1} then {

        # Refresh the OAuth2 access token, and if successful, save the new (refreshed) access token and try authenticating again.
        set oauth2 [new_CkOAuth2]

        # Use your actual Directory (tenant) ID instead of "112d7ed6-71bf-4eba-a866-738364321bfc"
        CkOAuth2_put_TokenEndpoint $oauth2 "https://login.microsoftonline.com/112d7ed6-71bf-4eba-a866-738364321bfc/oauth2/v2.0/token"

        # Replace these with your Azure App Registration's actual values.
        CkOAuth2_put_ClientId $oauth2 "CLIENT_ID"
        CkOAuth2_put_ClientSecret $oauth2 "CLIENT_SECRET"

        # Get the "refresh_token"
        CkOAuth2_put_RefreshToken $oauth2 [CkJsonObject_stringOf $jsonToken "refresh_token"]

        # Send the HTTP POST to refresh the access token..
        set success [CkOAuth2_RefreshAccessToken $oauth2]
        if {$success != 1} then {
            puts [CkOAuth2_lastErrorText $oauth2]
            delete_CkJsonObject $jsonToken
            delete_CkImap $imap
            delete_CkOAuth2 $oauth2
            exit
        }

        puts "New access token: [CkOAuth2_accessToken $oauth2]"
        puts "New refresh token: [CkOAuth2_refreshToken $oauth2]"

        # Update the JSON with the new tokens.
        CkJsonObject_UpdateString $jsonToken "access_token" [CkOAuth2_accessToken $oauth2]
        CkJsonObject_UpdateString $jsonToken "refresh_token" [CkOAuth2_refreshToken $oauth2]

        # Save the new JSON access token response to a file.
        set sbJson [new_CkStringBuilder]

        CkJsonObject_put_EmitCompact $jsonToken 0
        CkJsonObject_EmitSb $jsonToken $sbJson
        CkStringBuilder_WriteFile $sbJson "qa_data/tokens/office365.json" "utf-8" 0

        puts "New Access Token = [CkOAuth2_accessToken $oauth2]"

        # Retry the login.
        set success [CkImap_Login $imap "OFFICE365_EMAIL_ADDRESS" [CkJsonObject_stringOf $jsonToken "access_token"]]
        if {$success == 0} then {
            puts [CkImap_lastErrorText $imap]
            delete_CkJsonObject $jsonToken
            delete_CkImap $imap
            delete_CkOAuth2 $oauth2
            delete_CkStringBuilder $sbJson
            exit
        }

    }     else {
        # Show the last error text for the call to Login
        puts "$loginLastErrorText"
        delete_CkJsonObject $jsonToken
        delete_CkImap $imap
        delete_CkOAuth2 $oauth2
        delete_CkStringBuilder $sbJson
        exit
    }

} else {
    puts "O365 OAuth authentication is successful."
}

# Do something...
set success [CkImap_SelectMailbox $imap "Inbox"]
if {$success != 1} then {
    puts [CkImap_lastErrorText $imap]
    delete_CkJsonObject $jsonToken
    delete_CkImap $imap
    delete_CkOAuth2 $oauth2
    delete_CkStringBuilder $sbJson
    exit
}

# Your application can continue to do other things in the IMAP session....

# When finished, logout and close the connection.
set success [CkImap_Logout $imap]
set success [CkImap_Disconnect $imap]

puts "Finished."

delete_CkJsonObject $jsonToken
delete_CkImap $imap
delete_CkOAuth2 $oauth2
delete_CkStringBuilder $sbJson