# Mautic API OAuth

**URL:** <https://forum.mautic.org/t/mautic-api-oauth/3560>\
**Category:** Product Support\
**Created:** [April 21, 2016, 4:21am UTC](https://forum.mautic.org/t/mautic-api-oauth/3560 "2016-04-21T04:21:58Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mfuller](https://avatars.discourse-cdn.com/v4/letter/m/f14d63/32.png) [@mfuller](https://forum.mautic.org/u/mfuller)\
**Post date:** [April 21, 2016, 4:21am UTC](https://forum.mautic.org/t/mautic-api-oauth/3560/1 "2016-04-21T04:21:58Z")

</div>

Hi,  
  
  
  
I’m a little confused regarding the OAuth authentication, specifically the call $auth-\>accessTokenUpdated(). It never seems to return true. As a result I have make a call to $auth-\>getAccessTokenData(); and store the results before the call to accessTokenUpdated. Am i missing something? Thanks  
  
  
  
My sample code based on sample from [https://github.com/mautic/api-library:](https://github.com/mautic/api-library:)

Code:

session\_name("oauthtester"); session\_start();

require dirname( **DIR** ).’/vendor/autoload.php’;  
require ‘settings.php’;

use MauticAuthApiAuth;  
use MauticMauticApi;

// ApiAuth::initiate will accept an array of OAuth settings  
$settings = array(  
‘baseUrl’ =\> $baseUrl, // Base URL of the Mautic instance  
‘version’ =\> $version, // Version of the OAuth can be OAuth2 or OAuth1a. OAuth2 is the default value.  
‘clientKey’ =\> $clientKey, // Client/Consumer key from Mautic  
‘clientSecret’ =\> $clientSecret, // Client/Consumer secret key from Mautic  
‘callback’ =\> $callback // Redirect URI/Callback URI for this script  
);

if (isset($\_GET[‘oauth\_token’]) && isset($\_GET[‘oauth\_verifier’])) {  
$settings[‘accessToken’] = $\_GET[‘oauth\_token’];  
$settings[‘accessTokenSecret’] = $\_GET[‘oauth\_verifier’];  
}

// Initiate the auth object  
$auth = ApiAuth::initiate($settings);

if (isset($\_SESSION[‘accessTokenData’])) { //todo read from more permanent  
$auth-\>setAccessTokenDetails(json\_decode($\_SESSION[‘accessTokenData’], true));  
}

if ($auth-\>validateAccessToken()){  
echo ‘222  
’;  
$accessTokenData = $auth-\>getAccessTokenData();  
$\_SESSION[‘accessTokenData’] = json\_encode($accessTokenData); //todo save more permanently

if ($auth-\>accessTokenUpdated()) {  
echo ‘333  
’;  
$accessTokenData = $auth-\>getAccessTokenData();

```
//store access token data however you want

```

}

$leadApi = MauticApi::getContext(“leads”, $auth, $baseUrl .’/api/’);  
$leads = $leadApi-\>getList();  
echo ‘$leads =’ . print\_r($leads, true);  
}

---

<div class="post-metadata">

**Author:** ![mfuller](https://avatars.discourse-cdn.com/v4/letter/m/f14d63/32.png) [@mfuller](https://forum.mautic.org/u/mfuller)\
**Post date:** [April 21, 2016, 4:21am UTC](https://forum.mautic.org/t/mautic-api-oauth/3560/2 "2016-04-21T04:21:58Z")

</div>

Hi,

I’m a little confused regarding the OAuth authentication, specifically the call $auth-\>accessTokenUpdated(). It never seems to return true. As a result I have make a call to $auth-\>getAccessTokenData(); and store the results before the call to accessTokenUpdated. Am i missing something? Thanks

My sample code based on sample from [https://github.com/mautic/api-library:](https://github.com/mautic/api-library:)

[code]session\_name(“oauthtester”);  
session\_start();

require dirname( **DIR** ).’/vendor/autoload.php’;  
require ‘settings.php’;

use MauticAuthApiAuth;  
use MauticMauticApi;

// ApiAuth::initiate will accept an array of OAuth settings  
$settings = array(  
‘baseUrl’ =\> $baseUrl, // Base URL of the Mautic instance  
‘version’ =\> $version, // Version of the OAuth can be OAuth2 or OAuth1a. OAuth2 is the default value.  
‘clientKey’ =\> $clientKey, // Client/Consumer key from Mautic  
‘clientSecret’ =\> $clientSecret, // Client/Consumer secret key from Mautic  
‘callback’ =\> $callback // Redirect URI/Callback URI for this script  
);

if (isset($\_GET[‘oauth\_token’]) && isset($\_GET[‘oauth\_verifier’])) {  
$settings[‘accessToken’] = $\_GET[‘oauth\_token’];  
$settings[‘accessTokenSecret’] = $\_GET[‘oauth\_verifier’];  
}

// Initiate the auth object  
$auth = ApiAuth::initiate($settings);

if (isset($\_SESSION[‘accessTokenData’])) { //todo read from more permanent  
$auth-\>setAccessTokenDetails(json\_decode($\_SESSION[‘accessTokenData’], true));  
}

if ($auth-\>validateAccessToken()){  
echo ‘222  
’;  
$accessTokenData = $auth-\>getAccessTokenData();  
$\_SESSION[‘accessTokenData’] = json\_encode($accessTokenData); //todo save more permanently

if ($auth-\>accessTokenUpdated()) {  
echo ‘333  
’;  
$accessTokenData = $auth-\>getAccessTokenData();

```
//store access token data however you want

```

}

$leadApi = MauticApi::getContext(“leads”, $auth, $baseUrl .’/api/’);  
$leads = $leadApi-\>getList();  
echo ‘$leads =’ . print\_r($leads, true);  
}[/code]

---

<div class="post-metadata">

**Author:** ![mfuller](https://avatars.discourse-cdn.com/v4/letter/m/f14d63/32.png) [@mfuller](https://forum.mautic.org/u/mfuller)\
**Post date:** [April 25, 2016, 5:28pm UTC](https://forum.mautic.org/t/mautic-api-oauth/3560/3 "2016-04-25T17:28:11Z")

</div>

OK even if I make a call to $auth-\>getAccessTokenData(); and store the results before the call to accessTokenUpdated, I get token\_rejected [code] =\> 401 when I call $leadApi-\>getList(). So I’m doing something wrong.

Any ideas?

Thanks.

---

<div class="post-metadata">

**Author:** ![justlevine](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/justlevine/32/74_2.png) [@justlevine](https://forum.mautic.org/u/justlevine)\
**Post date:** [April 30, 2016, 7:20am UTC](https://forum.mautic.org/t/mautic-api-oauth/3560/4 "2016-04-30T07:20:37Z")

</div>

Good call, although it didn’t fix the issue ☹

---

<div class="post-metadata">

**Author:** ![tasselhof](https://avatars.discourse-cdn.com/v4/letter/t/b2d939/32.png) [@tasselhof](https://forum.mautic.org/u/tasselhof)\
**Post date:** [May 1, 2016, 2:28pm UTC](https://forum.mautic.org/t/mautic-api-oauth/3560/5 "2016-05-01T14:28:12Z")

</div>

Hi, this part is totally wrong:

```auto
if (isset($_GET['oauth_token']) && isset($_GET['oauth_verifier'])) {
  $settings['accessToken'] = $_GET['oauth_token'];
  $settings['accessTokenSecret'] = $_GET['oauth_verifier'];
}
```

The only way to obtain token is through $auth-\>getAccessTokenData();

Surprisingly, I started getting the token when I used `session_start()`

Steps to do next:

1. Make sure the SESSION is running
2. Dump the Session out to see what you have stored here
3. Try the packed API tester which is part of the API library to see if you can access Mautic through there
