<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

How to Obtain Tokens for an Okta OIDC Application Without a Browser Using Curl/Postman

API Access Management
Okta Classic Engine
Okta Identity Engine

Overview

Obtaining user-scoped OpenID Connect (OIDC) or OAuth 2.0 tokens for Single-Page Applications (SPA), web, or native applications without using a browser facilitates unit, integration, or end-to-end testing. Administrators can obtain these tokens by completing primary authentication to retrieve a session token, making an authorize request, and exchanging the authorization code for tokens.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • OpenID Connect (OIDC) and OAuth 2.0
  • Single-Page Applications (SPA), Web, or Native Applications
  • Implicit Flow or Authorization Code Flow

Solution

What are the prerequisites for obtaining tokens without a browser?

Gather the required tools and ensure the user meets the authentication requirements before proceeding.

  • Use Postman Collections for formatting requests. Both the Authentication and OpenID Connect collections are required.
  • Ensure Okta does not prompt the user for multifactor authentication (MFA) at the organization level.
  • External, federated, or social users cannot use this technique.

 

Complete Primary Authentication to Obtain a Session Token.

Perform a POST request to the /authn endpoint with the user credentials to obtain a session token.

  1. Submit a request to POST https://<oktaDomain>/api/v1/authn.
  2. Include the username and password in the JSON body.
  3. Verify the response status is SUCCESS.
  4. Copy the sessionToken value from the response.

 

NOTE: If the status is not SUCCESS, refer to the Primary Authentication API documentation to complete the transaction.

 

The following image demonstrates a successful primary authentication request in Postman.

Postman Example

 

Construct the Authorize Request

Exchange the session token for tokens or an authorization code by submitting a GET request to the authorize endpoint of the Org Authorization Server or a Custom Authorization Server.

  1. Submit a request to GET https://<oktaDomain>/oauth2/v1/authorize or GET https://<oktaDomain>/oauth2/<authorizationServerId>/authorize.
  2. Provide the following query parameters:
    • client_id: The ID of the application.
    • response_type: Set to id_token, token, or code.
    • response_mode: Set to form_post.
    • sessionToken: The value obtained in the previous step.
    • scope: Space-separated scopes (for example, openid profile).
    • redirect_uri: A registered sign-in redirect Uniform Resource Identifier (URI).
    • nonce and state: Arbitrary strings.
    • For Proof Key for Code Exchange (PKCE), include code_challenge and code_challenge_method.

 

The following image demonstrates a successful authorize request in Postman.

Postman Example

 

How does Okta respond to the authorize request?

The response from the authorize request depends on the configured flow and response type.

  • Implicit Flow: If the response_type is id_token or token, the tokens appear in the HTML body of the response. Implicit flow does not support PKCE.
  • Authorization Code Flow: If the response_type is code, the response contains a code value. Proceed to the next section to exchange the code for tokens.

 

Exchange the Authorization Code for Tokens

Submit a POST request to the token endpoint with the authorization code to retrieve the tokens for the Authorization Code flow.

  1. Submit a request to POST https://<oktaDomain>/oauth2/v1/token or POST https://<oktaDomain>/oauth2/<authorizationServerId>/token.
  2. Set the Content-Type header to application/x-www-form-urlencoded.
  3. Provide the grant_type, code, redirect_uri, client_id, and code_verifier (if using PKCE) in the request body.

 

The following image demonstrates a successful token request in Postman.

Postman Example

 

NOTE: This technique is intended for testing and debugging. Production requests to the /authorize endpoint must redirect the browser. Administrators cannot use Asynchronous JavaScript and XML (AJAX) with the /authorize endpoint.

 

Related References

Loading
How to Obtain Tokens for an Okta OIDC Application Without a Browser Using Curl/Postman | Okta Support