Sample code for 30+ languages & platforms
Xbase++

RSAP Union API - Get OAuth2 Access Token

See more _Miscellaneous_ Examples

Demonstrates how to get an OAuth2 access token for the RSAP Union API. Note: This uses the client credentials flow, which does NOT require an interactive engagement using a browser.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oHttp
LOCAL oJson
LOCAL oCert
LOCAL oPrivKey
LOCAL oResp
LOCAL oSbResponseBody
LOCAL oJResp
LOCAL nRespStatusCode

nSuccess := 0

//  This example assumes the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

oHttp := CreateObject("Chilkat.Http")

//  The following JSON is sent in the request body.

//  {
//    "grant_type": "client_credentials",
//    "client_id": 1234,
//    "client_secret": "23456abcde"
//  }

oJson := CreateObject("Chilkat.JsonObject")
oJson:UpdateString("grant_type", "client_credentials")
oJson:UpdateInt("client_id", 1234)
oJson:UpdateString("client_secret", "23456abcde")

oHttp:SetRequestHeader("Content-type", "application/json")

//  Add the client certificate TLS authentication.
oCert := CreateObject("Chilkat.Cert")
nSuccess := oCert:LoadFromFile("qa_data/certs_and_keys/union_client_certificate.crt")
IF (nSuccess == 0)
    ? oCert:LastErrorText
    oHttp:destroy()
    oJson:destroy()
    oCert:destroy()
    RETURN
ENDIF

oPrivKey := CreateObject("Chilkat.PrivateKey")
nSuccess := oPrivKey:LoadAnyFormatFile("qa_data/certs_and_keys/union_client_certificate.nopass.key", "")
IF (nSuccess == 0)
    ? oPrivKey:LastErrorText
    oHttp:destroy()
    oJson:destroy()
    oCert:destroy()
    oPrivKey:destroy()
    RETURN
ENDIF

//  Associate the private key with the cert.
//  This will fail if the private key is not actually the correct one that corresponds to the public key stored within the cert.
nSuccess := oCert:SetPrivateKey(oPrivKey)
IF (nSuccess == 0)
    ? oCert:LastErrorText
    oHttp:destroy()
    oJson:destroy()
    oCert:destroy()
    oPrivKey:destroy()
    RETURN
ENDIF

//  Tell HTTP to use the cert for client TLS certificate authentication.
nSuccess := oHttp:SetSslClientCert(oCert)
IF (nSuccess == 0)
    ? oHttp:LastErrorText
    oHttp:destroy()
    oJson:destroy()
    oCert:destroy()
    oPrivKey:destroy()
    RETURN
ENDIF

oResp := CreateObject("Chilkat.HttpResponse")
nSuccess := oHttp:HttpJson("POST", "https://api-test.rsap.ca/oauth/token", oJson, "application/json", oResp)
IF (nSuccess == 0)
    ? oHttp:LastErrorText
    oHttp:destroy()
    oJson:destroy()
    oCert:destroy()
    oPrivKey:destroy()
    oResp:destroy()
    RETURN
ENDIF

oSbResponseBody := CreateObject("Chilkat.StringBuilder")
oResp:GetBodySb(oSbResponseBody)
oJResp := CreateObject("Chilkat.JsonObject")
oJResp:LoadSb(oSbResponseBody)
oJResp:EmitCompact := 0

? "Response Body:"
? oJResp:Emit()

nRespStatusCode := oResp:StatusCode
? "Response Status Code = " + Str(nRespStatusCode)
IF (nRespStatusCode >= 400)
    ? "Response Header:"
    ? oResp:Header
    ? "Failed."
    oHttp:destroy()
    oJson:destroy()
    oCert:destroy()
    oPrivKey:destroy()
    oResp:destroy()
    oSbResponseBody:destroy()
    oJResp:destroy()
    RETURN
ENDIF

//  Sample JSON response:
//  (Sample code for parsing the JSON response is shown below)

//  {
//    "token_type": "Bearer",
//    "expires_in": 3600,
//    "access_token": "eyJ0eXAi...LnE"
//  }

//  This token expires in 1 hour.  Your application could re-use the same token for up to an hour,
//  or it can simply get a new access token before each request (if you're not doing too many requests).
nSuccess := oJResp:WriteFile("qa_data/tokens/rsapToken.json")

oHttp:destroy()
oJson:destroy()
oCert:destroy()
oPrivKey:destroy()
oResp:destroy()
oSbResponseBody:destroy()
oJResp:destroy()