OAuth 2 Advanced Options
The advanced options settings for Oauth2 are used to define how the access token should be handled.
data:image/s3,"s3://crabby-images/81899/818998afa0a6c05a05dc1d54bd6a60249829ee0b" alt="OAUth 2 Advanced Options OAUth 2 Advanced Options"
There are two available settings: how to sending, and how to handle refresh of the access token.
Send Access Token as:
This setting is used when you have
Header: Access token is sent as request header. Example:
Authorization: Bearer rRR0GnTudjuUUGaSt0n
Query: The access token is sent as a query parameter.
Example:
https://www.example.com/a/v1/y/{userId}?access_token=1/rRR0GnTudjuUUGaSt0n
Refresh Access Token:
The default settings is that SoapUI handles refresh tokens automatically and transparently. If you for some reason need tokens to time out, you can set refresh to manual.
Automatic: The refresh token is used automatically.
Manual: The token has to be manually applied.
When refresh access token is set to manual. A refresh button is made available next to the token.
data:image/s3,"s3://crabby-images/65a82/65a820bacf85dd3c8636746df104fcee8a13ae26" alt="Manual Refresh Manual Refresh"
To refresh the token, click the refresh button.
Access Token Expiration Time
The request can be set to use the access token expiration time provided from the server.
data:image/s3,"s3://crabby-images/36871/3687160cc36e4ffd63c02ea0b391d82c3b59a7d6" alt="Expiration Time Expiration Time"
Server: The expiration time provided by the authorization server is used.
Custom: The token expires after the set number of seconds, minutes or hours.
Note: By convention, the value "0" indicate that the token will never expire. There is no setting for immediate expiration of the token.