All Products
Search
Document Center

Identity as a Service:FetchOAuthAuthenticationToken

Last Updated:Jul 30, 2026

Retrieves a valid OAuth authentication token.

Operation description

This API authenticates and authorizes requests based on an Access Token issued by IDaaS.

Ensure that the Access Token you provide has the function authorization to "obtain authentication token" for the IDaaS built-in PAM application (Privileged Access Management).

Note

The corresponding scope is urn:cloud:idaas:pam|authentication_token:obtain.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

No authorization for this operation. If you encounter issues with this operation, contact technical support.

Request syntax

POST /v2/{instanceId}/authenticationTokens/_/actions/fetchOAuthAccessToken HTTP/1.1

Path Parameters

Parameter

Type

Required

Description

Example

instanceId

string

Yes

The instance ID.

idaas_ue2jvisn35ea5lmthk267xxxxx

Request parameters

Parameter

Type

Required

Description

Example

Authorization

string

Yes

The authentication information. Format: Bearer ${access_token}.

Note

Enter the Access Token issued by IDaaS.

Bearer xxxxxx

body

object

No

The request body.

{'key': 'value'}

credentialProviderIdentifier

string

Yes

The credential provider identifier.

test_example_identifier

scope

string

No

The scope corresponding to the OAuth protocol.

Note

If not specified, the scope of the issued OAuth Access Token defaults to the scope configuration of the corresponding credential provider.

Important Multiple scope values are separated by spaces.

example:test_01 example:test_02

forceAuthentication

boolean

No

Specifies whether to ignore existing valid tokens and force re-authorization. Default value: false.

false

customParameters

object

No

Custom key-value pairs appended to the OAuth authorization URL to pass additional parameters supported by the OAuth provider.

string

No

Additional parameters supported by the OAuth provider.

access_type=offline

Response elements

Element

Type

Description

Example

object

The OAuth authentication token details.

instanceId

string

The instance ID.

idaas_ue2jvisn35ea5lmthk267xxxxx

authenticationTokenId

string

The authentication token ID.

atntkn_01kqflm0sxxx8nmdc1cb5dskxxxxx

credentialProviderId

string

The credential provider ID.

atp_01kr2cmj5gxxx4fvmls2e93dxxxxx

createTime

integer

The creation time of the authentication token. This value is a UNIX timestamp in milliseconds.

1649830225000

updateTime

integer

The update time of the authentication token. This value is a UNIX timestamp in milliseconds.

1649830225000

authenticationTokenType

string

The authentication token type.

Note

The value is fixed as oauth_access_token, indicating an OAuth Access Token type authentication token.

Valid values:

  • oauth_access_token :

    oauth_access_token

oauth_access_token

revoked

boolean

Indicates whether the authentication token is revoked.

false

creatorType

string

The creator type of the authentication token.

Valid values:

  • application :

    application

application

creatorId

string

The creator ID of the authentication token.

app_ngtkgrrxxxxktg5eao6z4xxxxx

consumerType

string

The consumer type of the authentication token.

Valid values:

  • application :

    application

  • custom :

    custom

application

consumerId

string

The consumer ID of the authentication token.

app_ngtkgrrxxxxktg5eao6z4xxxxx

expirationTime

integer

The expiration time of the authentication token. This value is a UNIX timestamp in milliseconds.

1772693568000

oauthAccessTokenContent

object

The content of the OAuth Access Token type authentication token.

accessTokenValue

string

The access_token field in the OAuth protocol token endpoint response.

DgEBAGP2xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

tokenType

string

The token_type field in the OAuth protocol token endpoint response.

Bearer

scope

string

The scope field in the OAuth protocol token endpoint response.

example:test_01 example:test_02

oauthAuthorizationSession

object

The authorization session of the OAuth user_federation flow. Returned during first-time authorization or when user interaction is required.

sessionId

string

The authorization session ID.

atpoas_01l6losojlojbbv01adsq56xxxxx

authorizationUrl

string

The user authorization URL.

https://login.dingtalk.com/oauth2/auth?client_id=...

sessionUri

string

The authorization session URI.

urn:ietf:params:oauth:request_uri:atpoas_01l6ljnvrpc5niakl3gj3amxxxxxx

sessionStatus

string

The authorization session status.

Valid values:

  • pending :

    pending

pending

Examples

Success response

JSON format

{
  "instanceId": "idaas_ue2jvisn35ea5lmthk267xxxxx",
  "authenticationTokenId": "atntkn_01kqflm0sxxx8nmdc1cb5dskxxxxx",
  "credentialProviderId": "atp_01kr2cmj5gxxx4fvmls2e93dxxxxx",
  "createTime": 1649830225000,
  "updateTime": 1649830225000,
  "authenticationTokenType": "oauth_access_token",
  "revoked": false,
  "creatorType": "application",
  "creatorId": "app_ngtkgrrxxxxktg5eao6z4xxxxx",
  "consumerType": "application",
  "consumerId": "app_ngtkgrrxxxxktg5eao6z4xxxxx",
  "expirationTime": 1772693568000,
  "oauthAccessTokenContent": {
    "accessTokenValue": "DgEBAGP2xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx",
    "tokenType": "Bearer",
    "scope": "example:test_01 example:test_02"
  },
  "oauthAuthorizationSession": {
    "sessionId": "atpoas_yyy",
    "authorizationUrl": "https://auth.example.com",
    "sessionUri": "urn:ietf:params:oauth:request_uri:atpoas_yyy",
    "sessionStatus": "pending"
  }
}

Error codes

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.