Chilkat Online Tools

DataFlex / ForgeRock Identity Cloud Collection / Step 2: Get Access Token

Back to Collection Items

Use ChilkatAx-9.5.0-win32.pkg

Procedure Test
    Handle hoHttp
    Boolean iSuccess
    Variant vReq
    Handle hoReq
    Handle hoJsonParam1
    Handle hoJsonParam5
    Handle hoJsonParam6
    Variant vResp
    Handle hoResp
    String sTemp1
    Integer iTemp1
    Boolean bTemp1

    // This example assumes the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    Get Create (RefClass(cComChilkatHttp)) To hoHttp
    If (Not(IsComObjectCreated(hoHttp))) Begin
        Send CreateComObject of hoHttp

    Set ComBasicAuth Of hoHttp To True
    Set ComLogin Of hoHttp To "username"
    Set ComPassword Of hoHttp To "password"

    Get Create (RefClass(cComChilkatHttpRequest)) To hoReq
    If (Not(IsComObjectCreated(hoReq))) Begin
        Send CreateComObject of hoReq

    Get Create (RefClass(cComChilkatJsonObject)) To hoJsonParam1
    If (Not(IsComObjectCreated(hoJsonParam1))) Begin
        Send CreateComObject of hoJsonParam1
    Get ComEmit Of hoJsonParam1 To sTemp1
    Send ComAddParam To hoReq "client_id" sTemp1
    Send ComAddParam To hoReq "response_type" "token"
    Send ComAddParam To hoReq "scope" "write"
    Send ComAddParam To hoReq "decision" "allow"

    Get Create (RefClass(cComChilkatJsonObject)) To hoJsonParam5
    If (Not(IsComObjectCreated(hoJsonParam5))) Begin
        Send CreateComObject of hoJsonParam5
    Get ComEmit Of hoJsonParam5 To sTemp1
    Send ComAddParam To hoReq "csrf" sTemp1

    Get Create (RefClass(cComChilkatJsonObject)) To hoJsonParam6
    If (Not(IsComObjectCreated(hoJsonParam6))) Begin
        Send CreateComObject of hoJsonParam6
    Get ComEmit Of hoJsonParam6 To sTemp1
    Send ComAddParam To hoReq "redirect_uri" sTemp1
    Send ComAddParam To hoReq "state" "abc123"

    Get pvComObject of hoReq to vReq
    Get ComPostUrlEncoded Of hoHttp "https://<tenant-name>" vReq To vResp
    If (IsComObject(vResp)) Begin
        Get Create (RefClass(cComChilkatHttpResponse)) To hoResp
        Set pvComObject Of hoResp To vResp
    Get ComLastMethodSuccess Of hoHttp To bTemp1
    If (bTemp1 = False) Begin
        Get ComLastErrorText Of hoHttp To sTemp1
        Showln sTemp1

    Get ComStatusCode Of hoResp To iTemp1
    Showln iTemp1
    Get ComBodyStr Of hoResp To sTemp1
    Showln sTemp1
    Send Destroy of hoResp


Curl Command

curl -X POST
	-u 'username:password'
	-H "Content-Type: application/x-www-form-urlencoded"
	--data-urlencode 'client_id={{postmanPublicClientId}}'
	--data-urlencode 'response_type=token'
	--data-urlencode 'scope=write'
	--data-urlencode 'decision=allow'
	--data-urlencode 'csrf={{demoSSOToken}}'
	--data-urlencode 'redirect_uri={{redirect_uri}}'
	--data-urlencode 'state=abc123'

Postman Collection Item JSON

  "name": "Step 2: Get Access Token",
  "event": [
      "listen": "test",
      "script": {
        "exec": [
          "function QueryStringToJSON(qs) {            ",
          "    var keyvaluepairs = qs.slice(qs.indexOf(\"#\")+1).split('&');",
          "    ",
          "    var result = {};",
          "    keyvaluepairs.forEach(function(keyvaluepair) {",
          "        keyvaluepair = keyvaluepair.split('=');",
          "        result[keyvaluepair[0]] = decodeURIComponent(keyvaluepair[1] || '');",
          "    });",
          "    return JSON.parse(JSON.stringify(result));",
          "if(pm.response.code == 302)",
          "   let redirectLocation = QueryStringToJSON(pm.response.headers.get(\"Location\"));",
          "    pm.globals.set(\"implicitGrantAccessToken\", redirectLocation.access_token);",
          "    pm.globals.set(\"implicitGrantAccessToken\", \"ERROR: 302 not returned!\");",
          "// TESTS",
          "pm.test(\"Follow redirects is NOT enabled in Postman (Status code is 302)\", () => {",
          "  // If response was 302, ensure Postman is following redirects.  ",
          "pm.test(\"Response `Location` header contained `code` parameter\", () => {",
          "    let redirectLocation = QueryStringToJSON(pm.response.headers.get(\"Location\"));",
          "    pm.expect(redirectLocation.access_token)\"string\");",
        "type": "text/javascript"
  "protocolProfileBehavior": {
    "followRedirects": false
  "request": {
    "auth": {
      "type": "basic",
      "basic": [
          "key": "password",
          "value": "{{postmanClientSecret}}",
          "type": "string"
          "key": "username",
          "value": "{{postmanPublicClientId}}",
          "type": "string"
    "method": "POST",
    "header": [
        "key": "Content-Type",
        "name": "Content-Type",
        "value": "application/x-www-form-urlencoded",
        "type": "text"
    "body": {
      "mode": "urlencoded",
      "urlencoded": [
          "key": "client_id",
          "value": "{{postmanPublicClientId}}",
          "description": "The ID of the Public OAuth Client.",
          "type": "text"
          "key": "response_type",
          "value": "token",
          "description": "Response types the client will support and use.",
          "type": "text"
          "key": "scope",
          "value": "write",
          "description": "Strings that are presented to the user for approval and included in tokens so that the protected resource may make decisions about what to give access to.",
          "type": "text"
          "key": "decision",
          "value": "allow",
          "description": "Decision that grants access to the authentication code. When using a browser, the user would consent that the client can access their information. This flow can be used machine-to-machine, by assuming consent, for example between two services provided by the same organization.",
          "type": "text"
          "key": "csrf",
          "value": "{{demoSSOToken}}",
          "description": "SSO token of a ForgeRock user, to protect against cross-site request forgery.",
          "type": "text"
          "key": "redirect_uri",
          "value": "{{redirect_uri}}",
          "description": "The complete URI to which client redirects the user if the request is successful.",
          "type": "text"
          "key": "state",
          "value": "abc123",
          "type": "text"
    "url": {
      "raw": "{{amUrl}}/oauth2{{realm}}/authorize",
      "host": [
      "path": [
  "response": [
      "name": "Example - Location header contains access_token.",
      "originalRequest": {
        "method": "POST",
        "header": [
            "key": "Content-Type",
            "name": "Content-Type",
            "value": "application/x-www-form-urlencoded",
            "type": "text"
        "body": {
          "mode": "urlencoded",
          "urlencoded": [
              "key": "client_id",
              "value": "{{postmanPublicClientId}}",
              "description": "The ID of the Public OAuth Client.",
              "type": "text"
              "key": "response_type",
              "value": "token",
              "description": "Response types the client will support and use.",
              "type": "text"
              "key": "scope",
              "value": "write",
              "description": "Strings that are presented to the user for approval and included in tokens so that the protected resource may make decisions about what to give access to.",
              "type": "text"
              "key": "decision",
              "value": "allow",
              "description": "Decision that grants access to the authentication code. When using a browser, the user would consent that the client can access their information. This flow can be used machine-to-machine, by assuming consent, for example between two services provided by the same organization.",
              "type": "text"
              "key": "csrf",
              "value": "{{demoSSOToken}}",
              "description": "SSO token of a ForgeRock user, to protect against cross-site request forgery.",
              "type": "text"
              "key": "redirect_uri",
              "value": "{{redirect_uri}}",
              "description": "The complete URI to which client redirects the user if the request is successful.",
              "type": "text"
        "url": {
          "raw": "{{amUrl}}/oauth2{{realm}}/authorize",
          "host": [
          "path": [
      "status": "Found",
      "code": 302,
      "_postman_previewlanguage": "plain",
      "header": [
          "key": "X-Frame-Options",
          "value": "SAMEORIGIN"
          "key": "X-Content-Type-Options",
          "value": "nosniff"
          "key": "Cache-Control",
          "value": "no-store"
          "key": "Location",
          "value": ""
          "key": "Pragma",
          "value": "no-cache"
          "key": "Set-Cookie",
          "value": "OAUTH_REQUEST_ATTRIBUTES=DELETED; Expires=Thu, 01 Jan 1970 00:00:00 GMT; Path=/;; HttpOnly"
          "key": "Content-Length",
          "value": "0"
          "key": "Date",
          "value": "Thu, 13 Aug 2020 12:15:18 GMT"
      "cookie": [
      "body": ""