Retrieves a valid OAuth authentication token.
Operation description
This API authenticates and authorizes requests based on an Access Token issued by IDaaS.
Ensure that the Access Token you provide has the function authorization to "obtain authentication token" for the IDaaS built-in PAM application (Privileged Access Management).
The corresponding scope is urn:cloud:idaas:pam|authentication_token:obtain.
Try it now
Test
RAM authorization
Request syntax
POST /v2/{instanceId}/authenticationTokens/_/actions/fetchOAuthAccessToken HTTP/1.1
Path Parameters
|
Parameter |
Type |
Required |
Description |
Example |
| instanceId |
string |
Yes |
The instance ID. |
idaas_ue2jvisn35ea5lmthk267xxxxx |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| Authorization |
string |
Yes |
The authentication information. Format: Bearer ${access_token}. Note
Enter the Access Token issued by IDaaS. |
Bearer xxxxxx |
| body |
object |
No |
The request body. |
{'key': 'value'} |
| credentialProviderIdentifier |
string |
Yes |
The credential provider identifier. |
test_example_identifier |
| scope |
string |
No |
The scope corresponding to the OAuth protocol. Note
If not specified, the scope of the issued OAuth Access Token defaults to the scope configuration of the corresponding credential provider. Important Multiple scope values are separated by spaces. |
example:test_01 example:test_02 |
| forceAuthentication |
boolean |
No |
Specifies whether to ignore existing valid tokens and force re-authorization. Default value: false. |
false |
| customParameters |
object |
No |
Custom key-value pairs appended to the OAuth authorization URL to pass additional parameters supported by the OAuth provider. |
|
|
string |
No |
Additional parameters supported by the OAuth provider. |
access_type=offline |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The OAuth authentication token details. |
||
| instanceId |
string |
The instance ID. |
idaas_ue2jvisn35ea5lmthk267xxxxx |
| authenticationTokenId |
string |
The authentication token ID. |
atntkn_01kqflm0sxxx8nmdc1cb5dskxxxxx |
| credentialProviderId |
string |
The credential provider ID. |
atp_01kr2cmj5gxxx4fvmls2e93dxxxxx |
| createTime |
integer |
The creation time of the authentication token. This value is a UNIX timestamp in milliseconds. |
1649830225000 |
| updateTime |
integer |
The update time of the authentication token. This value is a UNIX timestamp in milliseconds. |
1649830225000 |
| authenticationTokenType |
string |
The authentication token type. Note
The value is fixed as Valid values:
|
oauth_access_token |
| revoked |
boolean |
Indicates whether the authentication token is revoked. |
false |
| creatorType |
string |
The creator type of the authentication token. Valid values:
|
application |
| creatorId |
string |
The creator ID of the authentication token. |
app_ngtkgrrxxxxktg5eao6z4xxxxx |
| consumerType |
string |
The consumer type of the authentication token. Valid values:
|
application |
| consumerId |
string |
The consumer ID of the authentication token. |
app_ngtkgrrxxxxktg5eao6z4xxxxx |
| expirationTime |
integer |
The expiration time of the authentication token. This value is a UNIX timestamp in milliseconds. |
1772693568000 |
| oauthAccessTokenContent |
object |
The content of the OAuth Access Token type authentication token. |
|
| accessTokenValue |
string |
The access_token field in the OAuth protocol token endpoint response. |
DgEBAGP2xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx |
| tokenType |
string |
The token_type field in the OAuth protocol token endpoint response. |
Bearer |
| scope |
string |
The scope field in the OAuth protocol token endpoint response. |
example:test_01 example:test_02 |
| oauthAuthorizationSession |
object |
The authorization session of the OAuth user_federation flow. Returned during first-time authorization or when user interaction is required. |
|
| sessionId |
string |
The authorization session ID. |
atpoas_01l6losojlojbbv01adsq56xxxxx |
| authorizationUrl |
string |
The user authorization URL. |
https://login.dingtalk.com/oauth2/auth?client_id=... |
| sessionUri |
string |
The authorization session URI. |
urn:ietf:params:oauth:request_uri:atpoas_01l6ljnvrpc5niakl3gj3amxxxxxx |
| sessionStatus |
string |
The authorization session status. Valid values:
|
pending |
Examples
Success response
JSON format
{
"instanceId": "idaas_ue2jvisn35ea5lmthk267xxxxx",
"authenticationTokenId": "atntkn_01kqflm0sxxx8nmdc1cb5dskxxxxx",
"credentialProviderId": "atp_01kr2cmj5gxxx4fvmls2e93dxxxxx",
"createTime": 1649830225000,
"updateTime": 1649830225000,
"authenticationTokenType": "oauth_access_token",
"revoked": false,
"creatorType": "application",
"creatorId": "app_ngtkgrrxxxxktg5eao6z4xxxxx",
"consumerType": "application",
"consumerId": "app_ngtkgrrxxxxktg5eao6z4xxxxx",
"expirationTime": 1772693568000,
"oauthAccessTokenContent": {
"accessTokenValue": "DgEBAGP2xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx",
"tokenType": "Bearer",
"scope": "example:test_01 example:test_02"
},
"oauthAuthorizationSession": {
"sessionId": "atpoas_yyy",
"authorizationUrl": "https://auth.example.com",
"sessionUri": "urn:ietf:params:oauth:request_uri:atpoas_yyy",
"sessionStatus": "pending"
}
}
Error codes
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.