You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 2abdc32
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: EXAMPLES.md
+62Lines changed: 62 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -124,6 +124,68 @@ async with httpx.AsyncClient() as client:
124
124
125
125
More info: [Client Credentials Flow](https://auth0.com/docs/get-started/authentication-and-authorization-flow/client-credentials-flow)
126
126
127
+
## Access Token for a Connection (Token Vault)
128
+
129
+
`get_access_token_for_connection()` exchanges the user's Auth0 access token for a token from a federated identity provider (such as Google) via Auth0's Token Vault.
130
+
131
+
Three things must exist on your Auth0 tenant before this works. The Token Vault grant must be enabled on your application, which must be a confidential (resource-server) client. The connection (for example `google-oauth2`) must be configured and enabled on that application. The user must have linked their account through Auth0's Connected Accounts flow. See the [Token Vault setup guide](https://auth0.com/docs/secure/tokens/token-vault/configure-token-vault) for the application setup and the [Connected Accounts guide](https://auth0.com/docs/secure/tokens/token-vault/connected-accounts-for-token-vault) for the user-linking step.
132
+
133
+
### Basic call
134
+
135
+
```python
136
+
import httpx
137
+
138
+
from auth0_api_python import ApiClient, ApiClientOptions
Pass a `token_store` to cache the connection token. The SDK caches by `sub` (caller) and `connection`, skipping the exchange on repeat calls for the same user and provider. Pass `verified=` with the result of `verify_access_token()` to reuse that verification rather than running it again inside the exchange.
164
+
165
+
```python
166
+
from auth0_api_python import ApiClient, ApiClientOptions
167
+
168
+
# token_store is your AbstractTokenStore implementation.
169
+
# See docs/TokenStorage.md for how to build one and for encryption details.
Copy file name to clipboardExpand all lines: README.md
+2Lines changed: 2 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -122,6 +122,8 @@ async def main():
122
122
asyncio.run(main())
123
123
```
124
124
125
+
When a `token_store` is configured on `ApiClientOptions`, the connection token is cached by caller and connection, skipping the exchange on repeat calls. Pass `verified=` to reuse an already-verified token rather than verifying a second time. See [Access Token for a Connection](EXAMPLES.md#access-token-for-a-connection-token-vault) for a full example and setup requirements.
126
+
125
127
More info https://auth0.com/docs/secure/tokens/token-vault
Copy file name to clipboardExpand all lines: docs/TokenStorage.md
+5-4Lines changed: 5 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,9 +1,6 @@
1
1
# Token Storage
2
2
3
-
The SDK can cache access tokens it mints on the caller's behalf. Currently this covers tokens
4
-
returned by `get_token_on_behalf_of()`. This is separate from the `CacheAdapter` described in the
5
-
[Caching Guide](Caching.md), which only caches OIDC discovery metadata and JWKS keys, never a live
6
-
bearer token.
3
+
The SDK can cache access tokens it mints on the caller's behalf. The same store covers tokens returned by `get_token_on_behalf_of()`, M2M tokens from `get_client_credentials_token()`, and federated-connection tokens from `get_access_token_for_connection()`. This is separate from the `CacheAdapter` described in the [Caching Guide](Caching.md), which only caches OIDC discovery metadata and JWKS keys, never a live bearer token.
7
4
8
5
## Default Behavior
9
6
@@ -14,6 +11,10 @@ To enable caching, pass a `token_store` to `ApiClientOptions`. Once a store is c
14
11
automatically builds a cache key from the incoming token and no additional argument is needed per
15
12
call.
16
13
14
+
## Cache Key Shapes
15
+
16
+
The store uses a different cache key for each exchange method. OBO tokens from `get_token_on_behalf_of()` use the most detailed key, incorporating verified issuer, incoming client, exchange tenant and client, audience, organization, session, and granted scopes (see [On Behalf Of Exchange with Caching](#on-behalf-of-exchange-with-caching) for the full design). M2M tokens from `get_client_credentials_token()` are keyed on tenant, client, audience, and the requested scope set because the server is the identity and there is no user `sub`. Connection tokens from `get_access_token_for_connection()` are keyed on tenant, client, `sub` (the caller), and `connection` with no scope dimension, since the federated provider determines what scopes apply.
17
+
17
18
## On Behalf Of Exchange with Caching
18
19
19
20
The following example verifies an incoming token and exchanges for a downstream token. The result
options: Options for retrieving an access token for a connection.
734
745
Must include 'connection' and 'access_token' keys.
735
746
May optionally include 'login_hint'.
747
+
verified: The already-verified token, supplied by a caller that has verified it (for
748
+
example an MCP server). When omitted and a token_store is configured, the
749
+
token is verified here before any cache lookup.
736
750
737
751
Raises:
738
752
GetAccessTokenForConnectionError: If there was an issue requesting the access token.
739
753
ApiError: If the token exchange endpoint returns an error.
754
+
VerifyAccessTokenError: If a store is configured and either verified is omitted and the token fails verification, or verified is supplied but does not match the access token being exchanged.
740
755
741
756
Returns:
742
757
Dictionary containing the token response with access_token, expires_in, and scope.
0 commit comments