请求TCN API(https://auth.tcn.com/authorize)的OAuth 2.0授权码授予流程示例
Hey there! I’ve worked with the TCN API’s OAuth 2.0 Authorization Code grant flow before, so let me break down a practical, step-by-step example to help you get up and running smoothly.
Step 1: Redirect Your User to the TCN Authorization Endpoint
First, you’ll need to send your user to TCN’s authorization page to grant permissions. Construct a GET request URL with these required parameters:
GET https://auth.tcn.com/authorize? response_type=code &client_id=YOUR_CLIENT_ID &redirect_uri=YOUR_REGISTERED_REDIRECT_URI &scope=REQUESTED_PERMISSIONS &state=YOUR_RANDOM_SECURITY_STRING
Let’s break down each parameter:
response_type=code: Tells TCN you’re using the Authorization Code grant typeclient_id: The unique ID assigned to your app when you registered it with TCNredirect_uri: The exact callback URL you registered in your TCN developer dashboard (must match perfectly—HTTPS, path, all included)scope: The specific permissions your app needs (e.g.,read:call_dataorwrite:campaigns; check TCN’s docs for valid scopes)state: A random string you generate to prevent CSRF attacks. You’ll validate this value when TCN redirects back to you.
Step 2: Handle the Authorization Callback
Once the user grants permission, TCN will redirect them back to your redirect_uri with two key URL parameters: code (your authorization code) and state (the same string you sent earlier). For example:
https://your-app.com/tcn-callback?code=abc123xyz&state=your-random-string
First, verify that the state parameter matches the one you initially sent—this ensures the request is legitimate and not a CSRF attack. Then, grab the code value to use in the next step.
Step 3: Exchange the Authorization Code for an Access Token
Now, send a POST request to TCN’s token endpoint (typically https://auth.tcn.com/token—confirm this in TCN’s docs if needed) to swap the authorization code for an access token:
POST https://auth.tcn.com/token Content-Type: application/x-www-form-urlencoded grant_type=authorization_code &code=YOUR_AUTHORIZATION_CODE &redirect_uri=YOUR_REGISTERED_REDIRECT_URI &client_id=YOUR_CLIENT_ID &client_secret=YOUR_CLIENT_SECRET // Only include this if you’re a confidential client (e.g., backend app)
Important notes here:
- Confidential clients (like server-side apps) need to include the
client_secret; public clients (like SPAs or mobile apps) should never expose this, so omit it. - The request must use the
application/x-www-form-urlencodedcontent type.
A successful response will look something like this:
{ "access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...", "token_type": "Bearer", "expires_in": 3600, "refresh_token": "def456ghi..." }
Step 4: Use the Access Token to Call TCN APIs
With your access token in hand, you can now make authenticated requests to TCN’s APIs. Include the token in the Authorization header:
GET https://api.tcn.com/your-target-endpoint Authorization: Bearer YOUR_ACCESS_TOKEN
Step 5: Refresh the Access Token (When It Expires)
Access tokens have a limited lifespan (usually 1 hour, as shown in expires_in). When yours expires, use the refresh token to get a new access token without asking the user to re-authenticate:
POST https://auth.tcn.com/token Content-Type: application/x-www-form-urlencoded grant_type=refresh_token &refresh_token=YOUR_REFRESH_TOKEN &client_id=YOUR_CLIENT_ID &client_secret=YOUR_CLIENT_SECRET // Again, only for confidential clients
Quick Tips to Avoid Headaches
- Double-check that your
redirect_urimatches exactly what’s in your TCN developer settings—even a trailing slash difference can break the flow. - Store access tokens and refresh tokens securely: in server-side storage for confidential apps, or using secure browser storage (like HttpOnly cookies) for public apps.
- Always refer to TCN’s official documentation for the latest scopes, endpoint URLs, and any edge cases specific to their implementation.
内容的提问来源于stack exchange,提问作者Tarun Bhalodi

