OAuth 2.0

Authentication is the process of proving your identity to the system. The KPN API Store uses the OAuth 2.0 Client Credentials Grant type: Client ID and Client secret.


Where can I find my credentials

  • Sandbox: Click on Sandbox to see your Client ID and Client secret for all APIs in the Sandbox.
  • Project: Click on a project in Projects to see your Client ID and Client secret for all APIs in that project.

Use them for authorization in SwaggerHub or when you send an API request to the KPN API Store, for example with Postman or in a cURL request. You will receive an access token in the JSON message body of the response.

For example: "access_token": "haf2SDl07E9N7RluNQ4kJ1TkGgso".


Authentication workflow

Authentication workflow


How to authenticate

To authenticate on the KPN API Store use one of the following 3 options:


cURL

Execute the cURL command to receive an access token. Replace APP_CLIENT_ID and APP_CLIENT_SECRET with your credentials (Client ID and Client secret).

curl -X POST \
 'https://api-prd.kpn.com/oauth/client_credential/accesstoken?grant_type=client_credentials' \
 -H 'content-type: application/x-www-form-urlencoded' \
 -d 'client_id=APP_CLIENT_ID&client_secret=APP_CLIENT_SECRET'

If you are using cURL for Windows, please use the command below instead.

curl -X POST "https://api-prd.kpn.com/oauth/client_credential/accesstoken?grant_type=client_credentials" -H "content-type: application/x-www-form-urlencoded" -d "client_id=APP_CLIENT_ID&client_secret=APP_CLIENT_SECRET"

The authentication service returns a JSON message that contains the access_token field.

Successful HTTP Status: 200
{
    "refresh_token_expires_in": "0",
    "api_product_list": "[xxxxxx]",
    "organization_name": "kpn",
    "developer_email": "demo123@kpn.com",
    "token_type": "Bearer",
    "issued_at": "1587458037687",
    "client_id": "APP_CLIENT_ID",
    "access_token": "staG765sBUuai4OMeZiTful6PTRt",
    "application_name": "test_application",
    "level": "demo",
    "scope": "",
    "expires_in": "3599",
    "refresh_token": "",
    "refresh_count": "0",
    "status": "approved"
}


SwaggerHub

  1. Open the API reference of the API you want to use on top of the documentation page.
  2. Click on the Authorize button on the top right.
  3. In the form, fill in client_id and client_secret, using your credentials (Client ID and Client secret).
  4. Click Authorize.

Note: Even if the button says Authorize it's really the authentication process.


Postman

When using Postman, you will have to import the Swagger file into a Postman collection as follows:

  1. Open the API reference on SwaggerHub.
  2. On the top right, click Export, click Download API and click 'YAML Unresolved'.
  3. In Postman from the menu click File and click Import... Choose the YAML file you downloaded in the previous step. A new collection will be added.
  4. Select Get Access Token from the collection.
  5. Make sure the right environment is selected, corresponding to the API.
  6. Edit the environment variables client_id and client_secret, using your credentials (Client ID and Client secret).
  7. Check the response code and message.
  8. Press the Send button to get an access token.

Note: Request variables are no longer linked to an environment, but to the collection.