You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何自定义Doorkeeper生成的Access Token及令牌响应

Customizing Doorkeeper Access Tokens: Responses, Attributes, and Token Generation

Hey there! Let's break down how to handle your Doorkeeper Access Token customization needs step by step:

1. Customizing the Access Token Response

Doorkeeper gives you two flexible ways to tweak the JSON response returned when an access token is created:

Option 1: Use the custom_response config block

Add this to your config/initializers/doorkeeper.rb to directly modify the response payload with minimal code:

Doorkeeper.configure do
  # ... keep your existing configuration settings
  custom_response do |token, options|
    # Start with default required fields, then merge in your custom data
    default_payload = {
      access_token: token.token,
      token_type: token.token_type,
      expires_in: token.expires_in,
      refresh_token: token.refresh_token
    }
    default_payload.merge({
      resource_owner_id: token.resource_owner_id,
      app_display_name: token.application&.name,
      your_custom_field: "any_value_you_need"
    })
  end
end

Option 2: Override the TokenResponse class

For more complex response logic (like fetching related model data), create a custom response class in app/lib/doorkeeper/custom_token_response.rb:

module Doorkeeper
  class CustomTokenResponse < TokenResponse
    def body
      # Call super to get the default response, then append custom fields
      super.merge({
        user_email: token.resource_owner&.email, # Pull data from your User model
        custom_metadata: "custom_data_for_frontend"
      })
    end
  end
end

Then reference this class in your Doorkeeper config:

Doorkeeper.configure do
  # ... existing configs
  access_token_response_class Doorkeeper::CustomTokenResponse
end

2. Adding Custom Attributes to Access Tokens

To store custom data alongside the access token in the oauth_access_tokens table, follow these steps:

  1. Add database columns via a Rails migration:
rails generate migration AddCustomFieldsToOauthAccessTokens user_context:string preferences:text
rails db:migrate
  1. Whitelist the attributes in your Doorkeeper config (config/initializers/doorkeeper.rb):
Doorkeeper.configure do
  # ... existing configs
  access_token_attributes :user_context, :preferences
end
  1. Include custom attributes when creating tokens:
    Now you can pass your custom fields directly to the create! method:
Doorkeeper::AccessToken.create!(
  application_id: application_id,
  resource_owner_id: resource_owner_id,
  user_context: "mobile_app",
  preferences: { notification_enabled: true }.to_json
)

3. Customizing the Auto-Generated Access Token String

Doorkeeper uses SecureRandom.hex by default for token generation. To replace this with your own logic:

Option 1: Simple customization with a Proc

Add this to your Doorkeeper config to generate tokens in a different format (e.g., base64 instead of hex):

Doorkeeper.configure do
  # ... existing configs
  access_token_generator ->(token) { SecureRandom.base64(32) } # Generates a 44-character token
end

Option 2: Custom generator class for complex logic

For advanced use cases (like including user IDs, timestamps, or custom hashing), create app/lib/doorkeeper/custom_access_token_generator.rb:

module Doorkeeper
  class CustomAccessTokenGenerator < AccessTokenGenerator
    def generate(access_token)
      # Example: Combine resource owner ID, timestamp, and random string for uniqueness
      timestamp = Time.current.to_i
      random_segment = SecureRandom.hex(16)
      "#{access_token.resource_owner_id}_#{timestamp}_#{random_segment}"
    end
  end
end

Then register the generator in your config:

Doorkeeper.configure do
  # ... existing configs
  access_token_generator Doorkeeper::CustomAccessTokenGenerator
end

内容的提问来源于stack exchange,提问作者viveksrivastava

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 08:02:33