How to Obtain Tokens for an Okta OIDC Application Without a Browser Using Curl/Postman
Last Updated:
Overview
Obtaining user-scoped OpenID Connect (OIDC) or OAuth 2.0 tokens for Single-Page Applications (SPA), web, or native applications without using a browser facilitates unit, integration, or end-to-end testing. Administrators can obtain these tokens by completing primary authentication to retrieve a session token, making an authorize request, and exchanging the authorization code for tokens.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- OpenID Connect (OIDC) and OAuth 2.0
- Single-Page Applications (SPA), Web, or Native Applications
- Implicit Flow or Authorization Code Flow
Solution
What are the prerequisites for obtaining tokens without a browser?
Gather the required tools and ensure the user meets the authentication requirements before proceeding.
- Use Postman Collections for formatting requests. Both the Authentication and OpenID Connect collections are required.
- Ensure Okta does not prompt the user for multifactor authentication (MFA) at the organization level.
- External, federated, or social users cannot use this technique.
Complete Primary Authentication to Obtain a Session Token.
Perform a POST request to the /authn endpoint with the user credentials to obtain a session token.
- Submit a request to
POST https://<oktaDomain>/api/v1/authn. - Include the
usernameandpasswordin the JSON body. - Verify the response status is
SUCCESS. - Copy the
sessionTokenvalue from the response.
NOTE: If the status is not SUCCESS, refer to the Primary Authentication API documentation to complete the transaction.
The following image demonstrates a successful primary authentication request in Postman.
Construct the Authorize Request
Exchange the session token for tokens or an authorization code by submitting a GET request to the authorize endpoint of the Org Authorization Server or a Custom Authorization Server.
- Submit a request to
GET https://<oktaDomain>/oauth2/v1/authorizeorGET https://<oktaDomain>/oauth2/<authorizationServerId>/authorize. - Provide the following query parameters:
client_id: The ID of the application.response_type: Set toid_token,token, orcode.response_mode: Set toform_post.sessionToken: The value obtained in the previous step.scope: Space-separated scopes (for example,openid profile).redirect_uri: A registered sign-in redirect Uniform Resource Identifier (URI).nonceandstate: Arbitrary strings.- For Proof Key for Code Exchange (PKCE), include
code_challengeandcode_challenge_method.
The following image demonstrates a successful authorize request in Postman.
How does Okta respond to the authorize request?
The response from the authorize request depends on the configured flow and response type.
- Implicit Flow: If the
response_typeisid_tokenortoken, the tokens appear in the HTML body of the response. Implicit flow does not support PKCE. - Authorization Code Flow: If the
response_typeiscode, the response contains acodevalue. Proceed to the next section to exchange the code for tokens.
Exchange the Authorization Code for Tokens
Submit a POST request to the token endpoint with the authorization code to retrieve the tokens for the Authorization Code flow.
- Submit a request to
POST https://<oktaDomain>/oauth2/v1/tokenorPOST https://<oktaDomain>/oauth2/<authorizationServerId>/token. - Set the Content-Type header to
application/x-www-form-urlencoded. - Provide the
grant_type,code,redirect_uri,client_id, andcode_verifier(if using PKCE) in the request body.
The following image demonstrates a successful token request in Postman.
NOTE: This technique is intended for testing and debugging. Production requests to the /authorize endpoint must redirect the browser. Administrators cannot use Asynchronous JavaScript and XML (AJAX) with the /authorize endpoint.
