关于BIM360试用账户第三方应用获取Access Token的技术问询
Great question! Let's break down how to handle Access Token retrieval for BIM 360 trial accounts or accounts with fewer than 100 users (where manual API access enablement is blocked) after adding your app from the BIM 360 App Store.
Core Context First
Trial accounts and small BIM 360 accounts (<100 users) don't have the option to enable API access via the BIM 360 Admin portal. But apps published through the Autodesk App Store are pre-vetted and trusted by Autodesk, so they get a special pass to authenticate without that manual API toggle.
Step-by-Step Implementation
Ensure your app is a published App Store-compliant application
Only apps that are approved and listed in the Autodesk App Store can work with these restricted accounts. This is because Autodesk pre-associates trust and permissions for App Store apps, bypassing the need for account-level API enablement.Leverage the 3-legged OAuth 2.0 flow (App Store-adapted)
When a user clicks "Launch" on your app from the BIM 360 App Store, you'll need to guide them through Autodesk's standard OAuth flow—with a few key notes tailored to this scenario:- Redirect to Autodesk's authorization endpoint with these required parameters:
Yourhttps://developer.api.autodesk.com/authentication/v1/authorize ?client_id=YOUR_APP_CLIENT_ID &response_type=code &redirect_uri=YOUR_REGISTERED_REDIRECT_URI &scope=REQUIRED_BIM360_SCOPES (e.g., data:read, data:write, bucket:read) &state=RANDOM_CSRF_STRINGclient_idandredirect_urimust match what you registered in the Autodesk Developer Portal when you created your app for the App Store. - After the user logs in and grants permission, Autodesk will redirect back to your
redirect_uriwith an authorizationcode. - Exchange the code for tokens from Autodesk's token endpoint:
Send a POST request tohttps://developer.api.autodesk.com/authentication/v1/gettokenwith these form parameters:client_id: Your app's client IDclient_secret: Your app's client secret (from Developer Portal)code: The authorization code receivedgrant_type:authorization_coderedirect_uri: Same as used in the authorization step
- This will return your Access Token (short-lived) and Refresh Token (for getting new Access Tokens without re-authenticating the user).
- Redirect to Autodesk's authorization endpoint with these required parameters:
Account for restricted permissions
Keep in mind that Access Tokens from these restricted accounts will have limited scope—you won't be able to access account-level admin APIs, only data tied to the user's specific BIM 360 projects. Autodesk automatically enforces these limits, so you don't need to handle extra checks beyond standard API error handling.
Key Notes
- You don't need to ask users to enable API access in the BIM 360 Admin portal—this is impossible for their account type, and the App Store integration skips this requirement entirely.
- Custom, non-App Store integrations won't work for these accounts—only pre-vetted App Store apps can authenticate successfully here.
内容的提问来源于stack exchange,提问作者Bandu W

