0
votes

The documentation for provision grant says near the bottom of the page: https://developers.box.com/provision/

"If this token is expired or lost after the initial provisioning request, you can send an authorization code grant to https://api.box.com/oauth2/token with these additional parameters:" (scope, folder). "Additional parameters" to what exactly?

I've tried the following:

https://app.box.com/api/oauth2/token (POST)
grant_type      authorization_code
client_id       <app id>
client_secret   <app secret>
username        [email protected]
scope           folder_readwrite
folder_id       app_folder
code            ???

which says "code" is needed. I've tried about everything as the value of "code", but can't seem to make it happy. It just says "Auth code doesn't exist or is invalid for the client", which I know exists, as the provision grant tells me it does. If someone could write the canonical list of parameters and what is expected it would be appreciated!

I realize that the "normal" box authorization web-flow involves a code, but there is no code associated with provision grants. I need this to work, because I've seen the box api error, even though the user gets successfully set-up with the app folder.

1

1 Answers

0
votes

I believe that you need to have the user login if you lose access to the provision grant token (which is why you should try to keep it refreshed if possible). The documentation on provision grant says:

If this token is expired or lost after the initial provisioning request, you can send an authorization code grant to https://api.box.com/oauth2/token... The authorization code grant will require the user to log in to grant your application access again.

To get the auth code, follow the normal first leg of OAuth by having the user login with something like:

https://app.box.com/api/oauth2/authorize?response_type=code&client_id=MY_CLIENT_ID

Then extract the code from the query parameter sent to the redirect_uri you have configured for your application.

Once you have the auth code, you can then obtain a new provision grant access token:

curl https://app.box.com/api/oauth2/token \
-d 'grant_type=authorization_code&code={your_code}&client_id={your_client_id}&client_secret={your_client_secret}&scope=folder_readwrite&folder_id=app_folder' \
-X POST