Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

How to use POSTMAN rest client with magento REST api with Oauth. How to get Token and Token Secret?

Tags:

I am a beginner to magento REST API, how i will get token and token secret to be fill in Postman REST resquest. I have only consumer key and consumer secret. Please provide me the steps to follow.

like image 916
Deepak Kumar Avatar asked Jan 20 '15 12:01

Deepak Kumar


People also ask

How can I get customer token in Magento 2 REST API?

To generate a customer's access token, you must specify the customer's username and password in the payload. You do not specify an admin authorization token. By default, a customer token is valid for 1 hour. To change this value, click Stores > Settings > Configuration > Services > OAuth > Access Token Expiration.


2 Answers

First, you want to request a valid OAuth token and secret. Do this by hitting the /oauth/initiate URL of your Magento store with a GET parameter for oauth_callback. We're going to use httpbin so that we can echo anything that is passed to our callback. Make sure you have "Auto add parameters" checked on the OAuth 1.0 settings for Postman.

OAuth Token Request

That will give you an oauth_token and oauth_token_secret, which are only temporary. These are referred to as a "request token" and secret. Save these values somewhere because you will need them later.

OAuth Token Response

Now, assemble a new regular HTTP request to the /admin/oauth_authorize URL of your Magento store. This will return a login form where you can accept the oauth token and authorize your app, however since we're using Postman we aren't able to interact with the form.

OAuth Authorization Form

Instead, view the source and pull out the form_key hidden input value. Then assemble a new HTTP request to fake the submission of the authorization form. Make sure it is a POST request. Your new HTTP request should look like this.

OAuth Authorization Form Submit

Now, you need to actually confirm the authorization. Simply issue a GET to the /admin/oauth_authorize/confirm URL of your Magento store with the oauth_token as your parameter. When you send this request it will redirect to your oauth_callback from the first step. Now, you can see why we used httpbin as our callback in the first step.

OAuth Authorization Confirmation

OK. So, we're almost home. The last piece of the puzzle is to use the oauth_token, oauth_secret, and oauth_verifier all together to get a valid and persistent "access token". So, take the oauth_token_secret from the first step, and combine and assemble a new OAuth request like so.

OAuth Token

You should get a returned token and secret. These will never expire! You can use them to query products and stuff.

OAuth Token Response

Now, you can assemble your OAuth requests like this. Edit: Note, you must check the "Add params to header" checkbox in order for Magento REST calls to work properly.

OAuth REST Request

like image 101
Franklin P Strube Avatar answered Oct 07 '22 13:10

Franklin P Strube


Example request in Postman version 6.x.x

image.png

And response of this request is

image.png

You can get this credentials from Magento Admin. Click on edit icon in Integrations page.

image.png

like image 39
Farid Movsumov Avatar answered Oct 07 '22 13:10

Farid Movsumov