Chilkat Online Tools

delphiDll / Commercetools / Token Introspection

Back to Collection Items

var
http: HCkHttp;
success: Boolean;
resp: HCkHttpResponse;

begin
// This example assumes the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

http := CkHttp_Create();

CkHttp_putBasicAuth(http,True);
CkHttp_putLogin(http,'username');
CkHttp_putPassword(http,'password');

CkHttp_SetRequestHeader(http,'Content-Type','application/json');

resp := CkHttp_QuickRequest(http,'POST','https://domain.com/oauth/introspect?token={{ctp_access_token}}');
if (CkHttp_getLastMethodSuccess(http) = False) then
  begin
    Memo1.Lines.Add(CkHttp__lastErrorText(http));
    Exit;
  end;

Memo1.Lines.Add(IntToStr(CkHttpResponse_getStatusCode(resp)));
Memo1.Lines.Add(CkHttpResponse__bodyStr(resp));
CkHttpResponse_Dispose(resp);

CkHttp_Dispose(http);

Curl Command

curl -X POST
	-u 'username:password'
	-H "Content-Type: application/json"
https://domain.com/oauth/introspect?token={{ctp_access_token}}

Postman Collection Item JSON

{
  "name": "Token Introspection",
  "event": [
    {
      "listen": "test",
      "script": {
        "type": "text/javascript",
        "exec": [
          "tests[\"Status code is 200\"] = responseCode.code === 200;"
        ]
      }
    }
  ],
  "request": {
    "auth": {
      "type": "basic",
      "basic": {
        "username": "{{client_id}}",
        "password": "{{client_secret}}"
      }
    },
    "method": "POST",
    "header": [
      {
        "key": "Content-Type",
        "value": "application/json"
      }
    ],
    "body": {
      "mode": "raw",
      "raw": ""
    },
    "url": {
      "raw": "{{auth_url}}/oauth/introspect?token={{ctp_access_token}}",
      "host": [
        "{{auth_url}}"
      ],
      "path": [
        "oauth",
        "introspect"
      ],
      "query": [
        {
          "key": "token",
          "value": "{{ctp_access_token}}",
          "equals": true
        }
      ]
    },
    "description": "Token introspection allows to determine the active state of an OAuth 2.0 access token and to determine meta-information about this accces token, such as the `scope`."
  },
  "response": [
  ]
}