Chilkat Online Tools

Xojo / ForgeRock Identity Cloud Collection / Step 5: Introspect the Access Token

Back to Collection Items

// This example assumes the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

Dim http As New Chilkat.Http
Dim success As Boolean

Dim req As New Chilkat.HttpRequest

Dim jsonParam1 As New Chilkat.JsonObject
req.AddParam "token",jsonParam1.Emit()

Dim jsonParam2 As New Chilkat.JsonObject
req.AddParam "client_id",jsonParam2.Emit()

req.AddHeader "Authorization","Bearer <access_token>"

Dim resp As Chilkat.HttpResponse
resp = http.PostUrlEncoded("https://<tenant-name>.forgeblocks.com/am/oauth2/realms/root/realms/alpha/introspect",req)
If (http.LastMethodSuccess = False) Then
    System.DebugLog(http.LastErrorText)
    Return
End If

Dim sbResponseBody As New Chilkat.StringBuilder
success = resp.GetBodySb(sbResponseBody)

Dim jResp As New Chilkat.JsonObject
success = jResp.LoadSb(sbResponseBody)
jResp.EmitCompact = False

System.DebugLog("Response Body:")
System.DebugLog(jResp.Emit())

Dim respStatusCode As Int32
respStatusCode = resp.StatusCode
System.DebugLog("Response Status Code = " + Str(respStatusCode))
If (respStatusCode >= 400) Then
    System.DebugLog("Response Header:")
    System.DebugLog(resp.Header)
    System.DebugLog("Failed.")

    Return
End If

// Sample JSON response:
// (Sample code for parsing the JSON response is shown below)

// {
//   "active": true,
//   "scope": "manage",
//   "realm": "/",
//   "client_id": "forgerockDemoPublicClient",
//   "user_id": "demo",
//   "token_type": "Bearer",
//   "exp": 1597324784,
//   "sub": "demo",
//   "iss": "http://openam.example.com:8080/openam/oauth2",
//   "auth_level": 0,
//   "authGrantId": "bdtxHp1kka6iin4Q2KpNgCfgcVs",
//   "auditTrackingId": "037f02f9-d821-4f72-8563-c5050c40fdc3-53256",
//   "expires_in": 3600
// }

// Sample code for parsing the JSON response...
// Use this online tool to generate parsing code from sample JSON: Generate JSON Parsing Code

Dim active As Boolean
active = jResp.BoolOf("active")
Dim scope As String
scope = jResp.StringOf("scope")
Dim realm As String
realm = jResp.StringOf("realm")
Dim client_id As String
client_id = jResp.StringOf("client_id")
Dim user_id As String
user_id = jResp.StringOf("user_id")
Dim token_type As String
token_type = jResp.StringOf("token_type")
Dim exp As Int32
exp = jResp.IntOf("exp")
Dim v_sub As String
v_sub = jResp.StringOf("sub")
Dim iss As String
iss = jResp.StringOf("iss")
Dim auth_level As Int32
auth_level = jResp.IntOf("auth_level")
Dim authGrantId As String
authGrantId = jResp.StringOf("authGrantId")
Dim auditTrackingId As String
auditTrackingId = jResp.StringOf("auditTrackingId")
Dim expires_in As Int32
expires_in = jResp.IntOf("expires_in")

Curl Command

curl -X POST
	-H "Authorization: Bearer <access_token>"
	--data-urlencode 'token={{access_token}}'
	--data-urlencode 'client_id={{postmanPublicClientId}}'
https://<tenant-name>.forgeblocks.com/am/oauth2/realms/root/realms/alpha/introspect

Postman Collection Item JSON

{
  "name": "Step 5: Introspect the Access Token",
  "event": [
    {
      "listen": "test",
      "script": {
        "exec": [
          "// Tests",
          "",
          "const jsonData = JSON.parse(responseBody);",
          "",
          "pm.test(\"Status code is 200\", () => {",
          "  pm.expect(pm.response.code).to.eql(200);",
          "});",
          "",
          "pm.test(\"Response contains correct `client_id`.\", function () {",
          "    pm.expect(jsonData.client_id).to.eql(pm.collectionVariables.get(\"postmanPublicClientId\"));",
          "});",
          ""
        ],
        "type": "text/javascript"
      }
    }
  ],
  "request": {
    "method": "POST",
    "header": [
    ],
    "body": {
      "mode": "urlencoded",
      "urlencoded": [
        {
          "key": "token",
          "value": "{{access_token}}",
          "description": "Access token you want to introspect.",
          "type": "text"
        },
        {
          "key": "client_id",
          "value": "{{postmanPublicClientId}}",
          "description": "The ID of the Confidential OAuth Client.",
          "type": "text"
        }
      ]
    },
    "url": {
      "raw": "{{amUrl}}/oauth2{{realm}}/introspect",
      "host": [
        "{{amUrl}}"
      ],
      "path": [
        "oauth2{{realm}}",
        "introspect"
      ]
    },
    "description": "Retrieve metadata about the active access token, such as, approved scopes, the user that authorized the token, and the expiry time."
  },
  "response": [
    {
      "name": "Example",
      "originalRequest": {
        "method": "POST",
        "header": [
        ],
        "body": {
          "mode": "urlencoded",
          "urlencoded": [
            {
              "key": "token",
              "value": "{{access_token}}",
              "description": "Access token you want to introspect.",
              "type": "text"
            },
            {
              "key": "client_id",
              "value": "{{postmanPublicClientId}}",
              "description": "The ID of the Confidential OAuth Client.",
              "type": "text"
            }
          ]
        },
        "url": {
          "raw": "{{amUrl}}/oauth2{{realm}}/introspect",
          "host": [
            "{{amUrl}}"
          ],
          "path": [
            "oauth2{{realm}}",
            "introspect"
          ]
        }
      },
      "status": "OK",
      "code": 200,
      "_postman_previewlanguage": "json",
      "header": [
        {
          "key": "X-Frame-Options",
          "value": "SAMEORIGIN"
        },
        {
          "key": "X-Content-Type-Options",
          "value": "nosniff"
        },
        {
          "key": "Content-Type",
          "value": "application/json;charset=UTF-8"
        },
        {
          "key": "Content-Length",
          "value": "346"
        },
        {
          "key": "Date",
          "value": "Thu, 13 Aug 2020 12:20:17 GMT"
        }
      ],
      "cookie": [
      ],
      "body": "{\n    \"active\": true,\n    \"scope\": \"manage\",\n    \"realm\": \"/\",\n    \"client_id\": \"forgerockDemoPublicClient\",\n    \"user_id\": \"demo\",\n    \"token_type\": \"Bearer\",\n    \"exp\": 1597324784,\n    \"sub\": \"demo\",\n    \"iss\": \"http://openam.example.com:8080/openam/oauth2\",\n    \"auth_level\": 0,\n    \"authGrantId\": \"bdtxHp1kka6iin4Q2KpNgCfgcVs\",\n    \"auditTrackingId\": \"037f02f9-d821-4f72-8563-c5050c40fdc3-53256\",\n    \"expires_in\": 3600\n}"
    }
  ]
}