# Need help to build OAuth 2.0 Authentication flow

**URL:** <https://discourse.nodered.org/t/need-help-to-build-oauth-2-0-authentication-flow/78056>\
**Category:** General\
**Tags:** http-request, security, function-node\
**Created:** [1 May 2023 00:21 UTC](https://discourse.nodered.org/t/need-help-to-build-oauth-2-0-authentication-flow/78056 "2023-05-01T00:21:50Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![amit\_meld](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/amit_meld/32/79510_2.png) [@amit\_meld](https://discourse.nodered.org/u/amit_meld)\
**Post date:** [1 May 2023 00:21 UTC](https://discourse.nodered.org/t/need-help-to-build-oauth-2-0-authentication-flow/78056/1 "2023-05-01T00:21:50Z")

</div>

Hi,

I am trying to do the OAuth 2.0 authentication using Node-red. I have a noise sensor called Minut which is a pretty famous noise sensor in commercial use cases such as AirBNB. Below is their API documentation from the website: [Minut API documentation](https://api.minut.com/latest/docs#overview--getting-started)

I am able to test the API using Postman by creating the bearer token which expires after a while and I need to regenerate it again manually. Now I want to keep pulling the events from the device and push them to a database I have set up. I have cliend\_id, client\_secret, and redirect\_uri from their support team for my device. By reading their API documentation it is understood that Authentication produces an Access token and refresh token. When the access token expires, the refresh token can be fed back to the server to produce an updated access token and optional refresh token. I believe that I should be having two HTTP request nodes with one function node in between to store the tokens I receive. I am not sure how can I store them as a global variable which updates automatically when injected and handles the authentication that returns the requested Events data from the API server. Could you please help me in generating this flow?

Kind regards,  
Amit Kulkarni

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [1 May 2023 05:26 UTC](https://discourse.nodered.org/t/need-help-to-build-oauth-2-0-authentication-flow/78056/2 "2023-05-01T05:26:35Z")

</div>

[https://flows.nodered.org/search?term=Oauth](https://flows.nodered.org/search?term=Oauth)

---

<div class="post-metadata">

**Author:** ![amit\_meld](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/amit_meld/32/79510_2.png) [@amit\_meld](https://discourse.nodered.org/u/amit_meld)\
**Post date:** [2 May 2023 00:11 UTC](https://discourse.nodered.org/t/need-help-to-build-oauth-2-0-authentication-flow/78056/3 "2023-05-02T00:11:25Z")

</div>

Awesome, I did not know there is a dedicated Oauth 2.0 node. I will use it and let you guys know if it worked. Thank you, Steve!

---

<div class="post-metadata">

**Author:** ![amit\_meld](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/amit_meld/32/79510_2.png) [@amit\_meld](https://discourse.nodered.org/u/amit_meld)\
**Post date:** [2 May 2023 06:41 UTC](https://discourse.nodered.org/t/need-help-to-build-oauth-2-0-authentication-flow/78056/4 "2023-05-02T06:41:00Z")

</div>

Hi,

I pulled the Oauth2 node down in nodered and below is the initial test flow I have setup :

 ![Screenshot 2023-05-02 at 4.28.42 pm](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/d/c/dc8126d1875cd5a5259ae6782cf9b7f873c326a4.png)

Below are the settings in Oauth2.0 node (Hidden username and client id for security) :

 ![Screenshot 2023-05-02 at 4.30.17 pm](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/7/b/7bd14da4c17196ec71e9bbfb3551c9f18fe40082.png)

Not sure but I have added the below header as given in API documentation :  
 ![Screenshot 2023-05-02 at 4.33.10 pm](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/a/7/a71f0a7d1f47b8318e64a31999e6b9dabbefde24.png)

To see the response I added below code in function node :

```auto
var payload = msg.oauth2Response;
return msg;

```

Well, not sure how the access token will pop-up in below http request node to query the information, Do I use any headers hear? :

 ![Screenshot 2023-05-02 at 4.36.00 pm](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/7/3/73a98bfe34d2860d03ccf81c475336e45c1743e1.png)

OAuth 2.0 returns HTTP 200, ok status but Debug node is just showing 'Unauthorized'. And if I remove HTTP request node it shows the timestamp.

![Screenshot 2023-05-02 at 4.38.24 pm](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/5/7/57c4f31998d6ad064f2fb2dc97b41c9cf9ce1332.png)

![Screenshot 2023-05-02 at 4.39.28 pm](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/9/3/93cfcb0d3870c4ca2ba97954b52538f7921443f7.png)

Could you please guide me to understand how do I build above flow?

Please refer : [RFC 6749: The OAuth 2.0 Authorization Framework](https://www.rfc-editor.org/rfc/rfc6749)

---

<div class="post-metadata">

**Author:** ![amit\_meld](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/amit_meld/32/79510_2.png) [@amit\_meld](https://discourse.nodered.org/u/amit_meld)\
**Post date:** [2 May 2023 06:44 UTC](https://discourse.nodered.org/t/need-help-to-build-oauth-2-0-authentication-flow/78056/5 "2023-05-02T06:44:56Z")

</div>

Also, I am using the below link as an Access Token URL as instructed in minut api documentation :

htps://api.minut.com/v8/oauth/authorize?response\_type=code&client\_id=CLIENT\_ID&redirect\_uri=REDIRECT\_URI

I insert client\_id and redirect\_uri as provided by their support team for my device.

 ![Screenshot 2023-05-02 at 4.43.57 pm](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/4/4/44074f6d022c8c03d148d56cdef8d8e4c6533af5.png)

Minut API document : [Minut API documentation](https://api.minut.com/latest/docs#overview--getting-started)

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [2 May 2023 12:30 UTC](https://discourse.nodered.org/t/need-help-to-build-oauth-2-0-authentication-flow/78056/6 "2023-05-02T12:30:38Z")

</div>

Do you get your access token from the OAuth2 node?  
if so, your almost there:

Pass in a `headers` object to the request Node, and untick **Use authentication** on the Node also, I could be wrong, but the auth details cant be taken from a `msg` part in the node config 🤷‍♂️

```auto
msg.headers = {
    "Authorization": `Bearer ${msg.oauth2Response.access_token}`,
}

```

---

<div class="post-metadata">

**Author:** ![amit\_meld](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/amit_meld/32/79510_2.png) [@amit\_meld](https://discourse.nodered.org/u/amit_meld)\
**Post date:** [2 May 2023 23:43 UTC](https://discourse.nodered.org/t/need-help-to-build-oauth-2-0-authentication-flow/78056/7 "2023-05-02T23:43:43Z")

</div>

I am not sure if I am receiving access\_token from the OAuth2.0 node. How do I make debug show that?

Below is the flow I built and passed the token as Marcus suggested via the function node :

 ![Screenshot 2023-05-03 at 9.39.00 am](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/e/6/e63c4568f6dcdfece806500719ba504f59982b72.png)

```auto
msg.headers = {
    "Authorization": `Bearer ${msg.oauth2Response.access_token}`,
};
return msg;

```

It returned a 401 error, which means I am not receiving access\_token.  
 ![Screenshot 2023-05-03 at 9.41.18 am](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/9/f/9f435ea7a4499df38b588f1313edac60bfcf9f77.png)

Also, how does the refresh token work when access\_token expires and how to use it in the flow?

---

<div class="post-metadata">

**Author:** ![Sean-McG](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/sean-mcg/32/54677_2.png) [@Sean-McG](https://discourse.nodered.org/u/Sean-McG)\
**Post date:** [3 May 2023 00:20 UTC](https://discourse.nodered.org/t/need-help-to-build-oauth-2-0-authentication-flow/78056/8 "2023-05-03T00:20:42Z")

</div>

> [@amit\_meld](#):
>
> How do I make debug show that?

Add a debug node to the OAuth output and set output to show complete msg object

---

<div class="post-metadata">

**Author:** ![amit\_meld](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/amit_meld/32/79510_2.png) [@amit\_meld](https://discourse.nodered.org/u/amit_meld)\
**Post date:** [3 May 2023 01:06 UTC](https://discourse.nodered.org/t/need-help-to-build-oauth-2-0-authentication-flow/78056/9 "2023-05-03T01:06:25Z")

</div>

Below is the complete msg object :

 ![Screenshot 2023-05-03 at 10.48.28 am](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/1/3/13a3604776c2a1d73c57736e0ab748fd144336eb.png)

Here is how I receive access\_token manually :  
The URL given below I use in the Oauth2.0 node as an access token URL, if opened in browser takes us to the login page of minut sensor, I log in there, accept terms and conditions, then receive the authorization code embedded in the URL.

htps://api.minut.com/v8/oauth/authorize?response\_type=code&client\_id=CLIENT\_ID&redirect\_uri=REDIRECT\_URI

 ![Screenshot 2023-05-03 at 10.52.50 am](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/d/a/daa2da15771bfba692d7fd09102aacf28e2a48e6.png)

Code I receive after accepting :  
 ![Screenshot 2023-05-03 at 10.52.07 am](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/2/0/20ab8fffd7efa9e9d4b8f19fec40c07924c70827.png)

Then I fill the token endpoint form given in minut api document as given below and I receive access token once I hit the query - [Minut API documentation](https://api.minut.com/latest/docs#overview--getting-started)

 ![Screenshot 2023-04-18 at 10.12.14 am](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/6/0/60c4d6deba75ce6f5be066df4e1d34d6b4ea240e.png)

 ![Screenshot 2023-05-03 at 11.05.07 am](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/e/b/ebff87ae47507be3d95dc10778f87db7cf13826b.png)

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [3 May 2023 05:45 UTC](https://discourse.nodered.org/t/need-help-to-build-oauth-2-0-authentication-flow/78056/10 "2023-05-03T05:45:36Z")

</div>

Maybe try `https://api.minut.com/v8/oauth/authorize` for the URL in the OAuth2 node.

Whilst I use OAuth2 in work, I'm not 100% on its structure. Many pros here that do, but maybe the URL fix may get you the token 🤷‍♂️

The function JS code I posted I use often, and the `authorize` Url's do not have any parameters

---

<div class="post-metadata">

**Author:** ![amit\_meld](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/amit_meld/32/79510_2.png) [@amit\_meld](https://discourse.nodered.org/u/amit_meld)\
**Post date:** [10 May 2023 04:30 UTC](https://discourse.nodered.org/t/need-help-to-build-oauth-2-0-authentication-flow/78056/11 "2023-05-10T04:30:43Z")

</div>

Hello,

I am pleased to inform that I have successfully establish oauth2.0 and now receiving the access token to fetch the data via API.

Below is the flow I setup:

 ![Screenshot 2023-05-10 at 2.25.23 pm](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/5/1/515b379fb76fac9bf197d1d8aeaed7dbf358edf3.png)

```auto
let refreshToken = global.get('refreshToken');
let code = global.get('code');

msg.oauth2Request = { 
  "access_token_url": "https://api.minut.com/v8/oauth/token",
  "authorization_endpoint": "https://api.minut.com/v8/oauth/authorize",
  "credentials": {
    "grant_type": "client_credentials",
    "client_id": "<client id>",
    "client_secret": "<client secret>",
    "scope": "read",
    "refresh_token": refreshToken,
    "code": code
  },
};
console.log(refreshToken);
console.log(code);

```

I passed the above code to oauth 2.0 node and it returned the access token. and then used Marcus's JS code to pass the token to HTTP node. Thank you Marcus !

Below is the resulting output from the noise sensor API server :  
 ![Screenshot 2023-05-10 at 2.29.49 pm](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/a/4/a4b7c09513e9b219e6eaddb108372346ffd1d551.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [24 May 2023 04:31 UTC](https://discourse.nodered.org/t/need-help-to-build-oauth-2-0-authentication-flow/78056/12 "2023-05-24T04:31:13Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
