Sample code for 30+ languages & platforms
Zig

Refresh a Xero OAuth2 Access Token

See more Xero Examples

Refreshes a Xero OAuth2 access token. When an access token expires (after 1 hour), you will received a 401 status code indicating failure. When that happens, your application can run this code to refresh the access token, and then retry the request using the new access token. Refreshing an access token does not need user interaction (i.e. does not need to display a browser to have the user interactive authorize access).

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // It is assumed we previously obtained an OAuth2 access token.
    // This example loads the JSON access token file
    // saved by this example: Get Xero OAuth2 Access Token

    const json_token = try chilkat.JsonObject.init();
    defer json_token.deinit();
    json_token.loadFile("qa_data/tokens/xero-access-token.json") catch {
        std.debug.print("Failed to load xero-access-token.json\n", .{});
        return;
    };

    // The access token JSON looks like this:

    // {
    //   "id_token": "eyJhbGci...dqRs3MctS_g",
    //   "access_token": "eyJhbGci...sUoAhoQ",
    //   "expires_in": 1800,
    //   "token_type": "Bearer",
    //   "refresh_token": "2f77b...bfc2ee16f",
    //   "scope": "openid profile email accounting.transactions accounting.settings payroll.employees offline_access"
    // }

    const oauth2 = try chilkat.OAuth2.init();
    defer oauth2.deinit();

    oauth2.setTokenEndpoint("https://identity.xero.com/connect/token");

    // Replace these with actual values.
    oauth2.setClientId("XERO_APP_OAUTH2_CLIENT_ID");
    oauth2.setClientSecret("XERO_APP_OAUTH2_CLIENT_SECRET");
    oauth2.setUseBasicAuth(true);

    // Get the "refresh_token"
    oauth2.setRefreshToken(try json_token.stringOf(alloc, "refresh_token"));

    // Send the HTTP POST to refresh the access token..
    oauth2.refreshAccessToken() catch {
        std.debug.print("{s}\n", .{try oauth2.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("{s}\n", .{try oauth2.getAccessTokenResponse(alloc)});

    // The response contains a new access token and refresh token.
    // Update the JSON and re-save to the token file.
    json_token.updateString("access_token", try oauth2.getAccessToken(alloc)) catch {};
    json_token.updateString("refresh_token", try oauth2.getRefreshToken(alloc)) catch {};

    // Save the new JSON access token response to a file.
    const sb_json = try chilkat.StringBuilder.init();
    defer sb_json.deinit();
    json_token.setEmitCompact(false);
    json_token.emitSb(sb_json) catch {};
    sb_json.writeFile("qa_data/tokens/xero-access-token.json", "utf-8", false) catch {};

    std.debug.print("OAuth2 authorization granted!\n", .{});
    std.debug.print("New Access Token = {s}\n", .{try oauth2.getAccessToken(alloc)});
}