OAuth 2.0 token lifecycle
Learn how the Hybrid Service acquires, caches, refreshes, and secures OAuth 2.0 access tokens for outbound requests.
When an Enterprise Connector-enabled endpoint is configured to use OAuth 2.0 Target Security, the Hybrid Service manages the OAuth 2.0 access token automatically.
Token lifecycle
-
API Gateway receives the request and identifies that the target endpoint uses OAuth 2.0 Target Security.
-
API Gateway passes the OAuth 2.0 configuration to the Hybrid Service.
-
The Hybrid Service checks the in-memory token cache.
- If a valid (non-expired) token exists, the cached token is used.
- If no token exists or the token is nearing expiration, a new token is requested from the external authorization server.
-
The Hybrid Service adds the Bearer token to the outbound request.
-
The request is sent to the target API.
-
If the target API returns HTTP 401, the Hybrid Service discards the cached token, requests a new token, and retries the request.
-
The response is returned through API Gateway to the caller.
Token caching behavior
- Access tokens are stored in memory only and are not persisted.
- The token cache is thread-safe and shared across concurrent outbound requests.
- Tokens are refreshed before expiration to reduce the risk of request failures.
- After a Hybrid Service restart, tokens are acquired again when needed.
- This design supports both Client Credentials and Resource Owner Password Credentials (ROPC) because both grant types use short-lived access tokens.
Security model
- Communication with external authorization servers is secured by HTTPS.
- Client secrets and passwords are stored securely and are not exposed in API responses or logs.
- Token values are not logged. Only token lifecycle events are recorded.
- Only users with the IONAPI-Administrator role can access the OAuth 2.0 configuration.