Consuming Tokens Within an Application
Bridging the gap between user credentials and your application code
Overview
Don't-Repeat-Yourself is a fundamental principle of software development. While attaching an accessToken to an outgoing HTTP request may be simple, there is effort involved in checking if the token is expired, refreshing it if it is, and certainly in acquiring the token in the first place.
The fact that tokens expire makes their validity a function of time. Therefore, caching a token to be used later can easily run into issues when the token becomes expired. It's recommended to check for the token's expiration before using it.
Rather than writing the same token retrieval and validity checks over and over again, it's best to use an abstraction.
Introduction to the TokenOrchestrator abstract class
The TokenOrchestrator abstract class aims to be the aforementioned abstraction. It provides a clear pattern for your application behaviors:
- How should new tokens be acquired?
- How should tokens be stored?
- How should stored token be retrieved?
- How should expired tokens be handled?
Abstracting these ubiquitous patterns enables the downstream Token consumers to only concern themselves with consuming the token.
This is best illustrated by an example:
// `TokenOrchestrator` is an abstract class, use an implementation
const orchestrator = new TokenOrchestrator();
// `FetchClient` is available within the SDKs, see Guide page
const fetchClient = new FetchClient(orchestrator);
const response = await fetchClient.fetch('/api/messages');
const data = await response.json();
// Do something with data...Making an authenticated HTTP request is that simple! The TokenOrchestrator provides the FetchClient instance with a token to sign the outgoing request.
Included Implementations
Okta Client JavaScript includes a few implementations of TokenOrchestrator to support most common use cases.
Browsers
Recommended
AuthorizationCodeFlowOrchestrator– Implementation based on OAuth2: Authorization Code Flow.- Ideal for protecting Single-Page or standard web applications.
Advanced
HostOrchestrator– Delegates all token requests fromSubApp(aTokenOrchestratorimplementation) to a centralizedHost(an abstract class).- Well suited for large-scale applications, especially those developed by multiple teams.
Node.js
Coming Soon!
React Native
Coming Soon!