# How do I make accessToken and refreshToken from OAuth2 login available to flows?

**URL:** <https://discourse.nodered.org/t/how-do-i-make-accesstoken-and-refreshtoken-from-oauth2-login-available-to-flows/62138>\
**Category:** General\
**Created:** [3 May 2022 17:37 UTC](https://discourse.nodered.org/t/how-do-i-make-accesstoken-and-refreshtoken-from-oauth2-login-available-to-flows/62138 "2022-05-03T17:37:24Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![andersea](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/andersea/32/61015_2.png) [@andersea](https://discourse.nodered.org/u/andersea)\
**Post date:** [3 May 2022 17:37 UTC](https://discourse.nodered.org/t/how-do-i-make-accesstoken-and-refreshtoken-from-oauth2-login-available-to-flows/62138/1 "2022-05-03T17:37:24Z")

</div>

I managed to set up OAuth2 login using passport-oauth2.

In the verify function, I receive an accessToken and a refreshToken. (Equivalent to token and tokenSecret in other examples.)

```auto
                verify: function(accessToken, refreshToken, profile, done) {
                    done(null, { username: "Admin"});
                }

```

What is the best way to make this info available to running flows? I need the access token to make further API requests on a REST api that the authenticating service provides.

Should I just save it to a json file on disk?

---

<div class="post-metadata">

**Author:** ![Barbudor](https://avatars.discourse-cdn.com/v4/letter/b/4af34b/32.png) [@Barbudor](https://discourse.nodered.org/u/Barbudor)\
**Post date:** [4 May 2022 07:46 UTC](https://discourse.nodered.org/t/how-do-i-make-accesstoken-and-refreshtoken-from-oauth2-login-available-to-flows/62138/2 "2022-05-04T07:46:21Z")

</div>

I'm not using OAuth2 but I also get authentication tokens from another authentication service and I'm saving/retreiving them from the flow context along with their expirancy date.  
You can probably do the same with your OAuth2 tokens.

---

<div class="post-metadata">

**Author:** ![andersea](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/andersea/32/61015_2.png) [@andersea](https://discourse.nodered.org/u/andersea)\
**Post date:** [4 May 2022 16:34 UTC](https://discourse.nodered.org/t/how-do-i-make-accesstoken-and-refreshtoken-from-oauth2-login-available-to-flows/62138/3 "2022-05-04T16:34:48Z")

</div>

@Barbudor Thanks, but the verify function is defined in settings.js, not in a flow. The question is, how do I transfer the tokens into the active runtime from code running under settings.js.

See this example: [Securing Node-RED : Node-RED](https://nodered.org/docs/user-guide/runtime/securing-node-red#oauthopenid-based-authentication)

---

<div class="post-metadata">

**Author:** ![Barbudor](https://avatars.discourse-cdn.com/v4/letter/b/4af34b/32.png) [@Barbudor](https://discourse.nodered.org/u/Barbudor)\
**Post date:** [4 May 2022 17:15 UTC](https://discourse.nodered.org/t/how-do-i-make-accesstoken-and-refreshtoken-from-oauth2-login-available-to-flows/62138/4 "2022-05-04T17:15:53Z")

</div>

Ah ok.  
Still, it may be possible that the context functions are available in settings.js.  
May be you can try a `global.set("token", token)` in your verify function ?

---

<div class="post-metadata">

**Author:** ![andersea](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/andersea/32/61015_2.png) [@andersea](https://discourse.nodered.org/u/andersea)\
**Post date:** [25 June 2022 13:41 UTC](https://discourse.nodered.org/t/how-do-i-make-accesstoken-and-refreshtoken-from-oauth2-login-available-to-flows/62138/5 "2022-06-25T13:41:32Z")

</div>

Just to point future readers in some kind of direction, here is what I ended up doing. The verify function seems to run at a time, where the flow context is not available, so what I did instead was storing the access token on disk in a json file. Here is the verify function:

```auto
    verify: (accessToken, refreshToken, profile, done) => {
        const fs = require('fs');
        fs.writeFile('/data/accesstoken.json', JSON.stringify({ accessToken, refreshToken }),(err) => {
            console.log(err);
        });
        done(null, { username: "my@email.com"});
    }

```

I am using the node red docker container, which has the data folder in the path pointed to in the code above.

Now inside a flow I can set up a watch node to look for changes in that file path and load the new access token automatically after user login. Pretty simple solution and it works fine for my needs.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [9 July 2022 13:42 UTC](https://discourse.nodered.org/t/how-do-i-make-accesstoken-and-refreshtoken-from-oauth2-login-available-to-flows/62138/6 "2022-07-09T13:42:02Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
