Skip to content

Consuming Tokens Within an Application ​

Bridging the gap between user credentials and your application code ​

Overview ​

Don't-Repeat-Yourself is a fundamental principle of software development. While attaching an accessToken to an outgoing HTTP request may be simple, there is effort involved in checking if the token is expired, refreshing it if it is, and certainly in acquiring the token in the first place.

The fact that tokens expire makes their validity a function of time. Therefore, caching a token to be used later can easily run into issues when the token becomes expired. It's recommended to check for the token's expiration before using it.

Rather than writing the same token retrieval and validity checks over and over again, it's best to use an abstraction.

Introduction to the TokenOrchestrator abstract class ​

The TokenOrchestrator abstract class aims to be the aforementioned abstraction. It provides a clear pattern for your application behaviors:

  • How should new tokens be acquired?
  • How should tokens be stored?
  • How should stored token be retrieved?
  • How should expired tokens be handled?

Abstracting these ubiquitous patterns enables the downstream Token consumers to only concern themselves with consuming the token.

This is best illustrated by an example:

typescript
// `TokenOrchestrator` is an abstract class, use an implementation
const orchestrator = new TokenOrchestrator();
// `FetchClient` is available within the SDKs, see Guide page
const fetchClient = new FetchClient(orchestrator);

const response = await fetchClient.fetch('/api/messages');
const data = await response.json();

// Do something with data...

Making an authenticated HTTP request is that simple! The TokenOrchestrator provides the FetchClient instance with a token to sign the outgoing request.

Included Implementations ​

Okta Client JavaScript includes a few implementations of TokenOrchestrator to support most common use cases.

Browsers ​

  • AuthorizationCodeFlowOrchestrator – Implementation based on OAuth2: Authorization Code Flow.
    • Ideal for protecting Single-Page or standard web applications.

Advanced ​

  • HostOrchestrator – Delegates all token requests from SubApp (a TokenOrchestrator implementation) to a centralized Host (an abstract class).
    • Well suited for large-scale applications, especially those developed by multiple teams.

Node.js ​

Coming Soon!

React Native ​

Coming Soon!

See Also ​

abstract class TokenOrchestrator ​

Bridging the gap between user credentials and your application code ​

class AuthorizationCodeFlowOrchestrator ​

A TokenOrchestrator implementation based on Authorization Code Flow ​

class HostOrchestrator ​

A TokenOrchestrator implementation based on a host-delegation pattern ​

class FetchClient ​

A fetch wrapper to make authorized requests ​