OAuth Grant Types: 説明Summary<!-- /*NS Branding Styles*/ --> .ns-kb-css-body-editor-container { p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); } h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); } h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); } a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); } a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); } a:target { font-size: 12pt; color: var(--now-color--link-primary, #032D42); } a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } ul { font-size: 12pt; font-family: Lato; } li { font-size: 12pt; font-family: Lato; } img { display: ; max-width: ; width: ; height: ; } } OAuth では、Grant Type はクライアントがアクセストークンを取得する方法を定義します。以下は、OAuth で最も広く使用されている Grant Type の一部です。 Authorization Code Grant TypeResource Owner Password Credentials Grant TypeClient Credentials Grant TypeRefresh Token Grant Type 1. Authorization Code Grant Type Authorization Code Grant Type は、OAuth で最も広く使用されている Grant Type です。 本質的には 2 つのステージがあります。最初のステージでは、クライアントアプリケーションが認可サーバーまたはエンドポイントに認可コードを要求します。2 番目のステージでは、クライアントアプリケーションが最初のステージで取得した認可コードを使用してトークンサーバーまたはエンドポイントに POST コールを実行し、トークンを受け取ります。 ステージ 1: これは認可サーバー/エンドポイントへの GET コールです。この GET コール中に、ユーザーは認可エンドポイントにリダイレクトされます。認証情報を入力すると、認可サーバーは設定されたリダイレクト URL に認可コードを返します。 Request: GET (Authorization Endpoint)?response_type=code&client_id={CLIENT ID}&redirect_uri={REDIRECT URI}&scope={SCOPES}&state={STATE} Response: {REDIRECT URI}?code={AUTHORIZATION CODE}&state={STATE} ステージ 2: このステージでは、トークンサーバー/エンドポイントへのコールが POST リクエストを使用して実行されます。このサーバー間通信は、トークン取得プロセス中にバックグラウンドで行われ、UI レベルでは表示されません。 Request: POST (Token Endpoint) Header Authorization : Basic <BASE64({CLIENT ID}:{CLIENT SECRET})> Body grant_type:authorization_code code:{AUTHORIZATION CODE} redirect_uri:{REDIRECT URI} client_id:{CLIENT ID} client_secret:{CLIENT SECRET} 注: client ID と client secret は、設定に応じてリクエストボディまたはリクエストヘッダーのいずれかで送信できます。 Response: {"access_token":"{ACCESS TOKEN}","refresh_token":"{REFRESH TOKEN}","scope":"scope","token_type":"Bearer","expires_in":"Lifetime in seconds"} 2. Resource Owner Password Credentials Grant Type Resource Owner Password Credentials Grant Type は、ユーザー名とパスワードを直接使用してアクセストークンを取得するために設計されています。 この Grant Type では、クライアントアプリケーションがトークンエンドポイント/サーバーに POST コールを実行して、アクセストークンとリフレッシュトークンを取得します。このプロセスでは、クライアントアプリケーションはユーザー名とパスワードを渡す必要があります。認証情報および client ID/client secret を確認した後、トークンプロバイダーはアクセストークンとリフレッシュトークンの両方を返します。 Request: POST (Token Endpoint) Body grant_type:password username:{USERNAME} password:{PASSWORD} client_id:{CLIENT ID} client_secret:{CLIENT SECRET} 注: client ID と client secret は、設定に応じてリクエストボディまたはリクエストヘッダーのいずれかで送信できます。 Response: {"access_token":"{ACCESS TOKEN}","refresh_token":"{REFRESH TOKEN}","scope":"scope","token_type":"Bearer","expires_in":"Lifetime in seconds"} 3. Client Credentials Grant Type Client Credentials Flow では、クライアントアプリケーションは client ID と client secret を使用してトークンプロバイダーからアクセストークンを取得します。 この Grant Type はアプリケーションレベルのアクセスに基づいて動作します。このプロセスでは、クライアントアプリケーションがトークンエンドポイント/サーバーに POST コールを実行し、client ID と client secret を渡してアクセストークンを取得します。ユーザー認証情報は関与しません。client ID と secret を確認した後、トークンプロバイダーはアクセストークンを返します。Client Credentials Grant Type はアクセストークンのみを扱い、リフレッシュトークンの概念はありません。 Request: POST (Token Endpoint) Body grant_type:client_credentials client_id:{CLIENT ID} client_secret:{CLIENT SECRET} 注: client ID と client secret は、設定に応じてリクエストボディまたはリクエストヘッダーのいずれかで送信できます。 Response: {"access_token":"{ACCESS TOKEN}","scope":"scope","token_type":"Bearer","expires_in":"Lifetime in seconds"} 4. Refresh Token Grant Type Refresh Token Grant Type は、既存のリフレッシュトークンを提供して新しいアクセストークンを取得するために設計されています。 このプロセスでは、クライアントアプリケーションがトークンエンドポイント/サーバーに POST コールを実行し、既存のリフレッシュトークンを渡して新しいアクセストークンを取得します。リフレッシュトークンを確認した後、トークンプロバイダーはアクセストークンを返します。 Request: POST (Token Endpoint) Body grant_type:refresh_token client_id:{CLIENT ID} client_secret:{CLIENT SECRET} refresh_token:{REFRESH TOKEN} 注: client ID と client secret は、設定に応じてリクエストボディまたはリクエストヘッダーのいずれかで送信できます。 Response: {"access_token":"{ACCESS TOKEN}","refresh_token":"{REFRESH TOKEN}","scope":"scope","token_type":"Bearer","expires_in":"Lifetime in seconds"} Release<!-- /*NS Branding Styles*/ --> .ns-kb-css-body-editor-container { p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); } h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); } h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); } a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); } a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); } a:target { font-size: 12pt; color: var(--now-color--link-primary, #032D42); } a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } ul { font-size: 12pt; font-family: Lato; } li { font-size: 12pt; font-family: Lato; } img { display: ; max-width: ; width: ; height: ; } } すべてのリリース