# OAuth2 for the first time

**URL:** <https://discourse.nodered.org/t/oauth2-for-the-first-time/100023>\
**Category:** General\
**Created:** [26 December 2025 09:53 UTC](https://discourse.nodered.org/t/oauth2-for-the-first-time/100023 "2025-12-26T09:53:10Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![nygma2004](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/nygma2004/32/1308_2.png) [@nygma2004](https://discourse.nodered.org/u/nygma2004)\
**Post date:** [26 December 2025 09:53 UTC](https://discourse.nodered.org/t/oauth2-for-the-first-time/100023/1 "2025-12-26T09:53:10Z")

</div>

I have used simple REST APIs in the past without authentication, and I am trying to wrap my head around OAuth2. The API I want to use is not Google.

I have seen a few oauth2 nodes for node-red that implement the authorization, getting and refreshing the token. Is there any particular node that you could recommend?

Do I understand it correctly that the OAuth process requests a Bearer token from the server and for the "actual" communication I can use simple HTTP Request nodes with the bearer token added to the header?

Thanks, and Merry Christmas who are reading this today 🙂

---

<div class="post-metadata">

**Author:** ![bakman2](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bakman2/32/6207_2.png) [@bakman2](https://discourse.nodered.org/u/bakman2)\
**Post date:** [26 December 2025 10:08 UTC](https://discourse.nodered.org/t/oauth2-for-the-first-time/100023/2 "2025-12-26T10:08:07Z")

</div>

I have [posted a flow a while back](https://discourse.nodered.org/t/node-red-contrib-netatmo-0-3-0-error-authenticate-error-unauthorized-client/79952/24) that should be able to help you to get going.

---

<div class="post-metadata">

**Author:** ![nygma2004](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/nygma2004/32/1308_2.png) [@nygma2004](https://discourse.nodered.org/u/nygma2004)\
**Post date:** [26 December 2025 10:09 UTC](https://discourse.nodered.org/t/oauth2-for-the-first-time/100023/3 "2025-12-26T10:09:11Z")

</div>

Thanks, I will give this a try.

---

<div class="post-metadata">

**Author:** ![juntiedt](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/juntiedt/32/58357_2.png) [@juntiedt](https://discourse.nodered.org/u/juntiedt)\
**Post date:** [30 December 2025 22:11 UTC](https://discourse.nodered.org/t/oauth2-for-the-first-time/100023/4 "2025-12-30T22:11:33Z")

</div>

I have it working with Net Atmo based on bakman2's flow.  
works perfectly.

---

<div class="post-metadata">

**Author:** ![nygma2004](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/nygma2004/32/1308_2.png) [@nygma2004](https://discourse.nodered.org/u/nygma2004)\
**Post date:** [7 January 2026 21:19 UTC](https://discourse.nodered.org/t/oauth2-for-the-first-time/100023/5 "2026-01-07T21:19:54Z")

</div>

I only had time to look into this, but I still feel a bit lost. Looking at the documentation of the API, I see an authorize and token endpoint:

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/3/d/3d9e5711bbce74b11c357639c468d676be0aa0e6.png)  
I assume in the Oauth configuration this goes into the the two URLs. But I have no idea how to get the Client ID and secret.

And if I had the IDs, than I need to complete the config, deploy your flow, click on the Authorize button to perform the first manual login, and after the token will be saved in the global variable, and refreshed every 55 minutes by the flow? That's how it is supposed to work?

---

<div class="post-metadata">

**Author:** ![bakman2](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bakman2/32/6207_2.png) [@bakman2](https://discourse.nodered.org/u/bakman2)\
**Post date:** [8 January 2026 05:26 UTC](https://discourse.nodered.org/t/oauth2-for-the-first-time/100023/6 "2026-01-08T05:26:53Z")

</div>

Ok that sounds like oauth and not oauth2.

---

<div class="post-metadata">

**Author:** ![nygma2004](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/nygma2004/32/1308_2.png) [@nygma2004](https://discourse.nodered.org/u/nygma2004)\
**Post date:** [8 January 2026 08:09 UTC](https://discourse.nodered.org/t/oauth2-for-the-first-time/100023/7 "2026-01-08T08:09:42Z")

</div>

Yes, I was thinking the same, but all the links in the document point to oauth2. I think it is probably unfortunate that they used "oauth" in the URI and not "oauth2" and "v1" probably just the version of their interface:

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/e/c/ec95bb4056af60a2e468a1d3c546366d93213a84.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [8 April 2026 08:10 UTC](https://discourse.nodered.org/t/oauth2-for-the-first-time/100023/8 "2026-04-08T08:10:04Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
