← Back to plugin index

OAuth2 Access Token String Value Provider

Description
Retrieves, caches and provides an access token. When this provider is used for the first time, an access token is obtained from the token endpoint using the client credentials grant and then cached. For subsequent requests, the token is retrieved from the cache until it expires.
Type name
OAuth2AccessTokenStringValueProvider
Class
com.airlock.iam.oauth2.application.configuration.valueprovider.OAuth2AccessTokenStringValueProviderConfig
May be used by
Properties
Client ID (clientId)
Description
Client ID identifying Airlock IAM at the authorization / token and resource endpoint of the OAuth 2.0 provider.
Only alphanumeric characters and '-_.' are allowed.
Attributes
String
Mandatory
Validation RegEx: [a-zA-Z0-9-_.]+
Example
example-app
Example
crypticyButUniqueAppId01953utjhu91823rih
Client Secret (clientSecret)
Description
Client secret used to verify the client.
Attributes
String
Mandatory
Sensitive
Access Token Request Method (accessTokenRequestMethod)
Description
HTTP method to use for Access Token requests.
Attributes
Plugin-Link
Optional
Assignable plugins
HTTP Client (httpClient)
Description
HTTP client used for token endpoint requests.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Token Endpoint Authentication (tokenEndpointAuthentication)
Description
Specifies how the client secret is included in requests to the token endpoint.

RFC 6749 suggests to use the HTTP Basic authentication scheme ('OAuth 2.0 Basic Auth Client Secret').

Attributes
Plugin-Link
Optional
Assignable plugins
Token Endpoint URL (tokenEndpointURL)
Description
Token endpoint URL to get Access Tokens.
Attributes
String
Mandatory
Example
https://airlock.com/auth/rest/oauth2/authorization-servers/asId/token
Example
https://accounts.google.com/o/oauth2/token
Example
https://login.live.com/oauth20_token.srf
Example
https://login.microsoftonline.com/tenantid/oauth2/v2.0/token
Scopes To Request (scopesToRequest)
Description
Scopes to request from the token endpoint.

Scopes may only contain the following characters: 0-9, A-Z, a-z, !, #, $, %, &, ', (, ), *, +, ',', -, ., /, :, ;, <, >, =, ?, @, [, ], ^, _, `, {, }, |, ~

Attributes
String-List
Optional
Access Token Time To Live [s] (timeToLive)
Description
Defines the duration in seconds an access token should be reused from the cache before it is refreshed. When configured, this value should be lower than the access token's expiry as otherwise, expired access tokens could be returned. If no specific Time to Live is configured, the IAM will use the access token's expires_in value minus 5 seconds. This ensures that the token remains valid for at least five more seconds when it's retrieved from the cache.
Attributes
Long
Optional
YAML Template (with default values)

type: OAuth2AccessTokenStringValueProvider
id: OAuth2AccessTokenStringValueProvider-xxxxxx
displayName: 
comment: 
properties:
  accessTokenRequestMethod:
  clientId:
  clientSecret:
  httpClient:
  scopesToRequest:
  timeToLive:
  tokenEndpointAuthentication:
  tokenEndpointURL: