Skip to main content

Refresh and use a Bearer Token Credential

Build the pattern where Payloads refreshes a bearer token and uses the Credential on outbound Payloads.

Refresh and use a Bearer Token Credential

Use a Bearer Token Credential when an API expects an Authorization: Bearer ... header and the token needs refreshing. The Credential stores token state; its generated Credential Payload defines the refresh request and writes the returned values.

Create the Credential

From the Integration, create a Bearer Token Credential. Enter the client details, initial tokens and duration required by the external API. Open the generated Token Payload relationship.

See Configure Bearer Token Credentials. Use test credentials for validation.

Configure the refresh Actions

In the Credential Payload, select HTTP Request. Edit Request Settings to set the token Endpoint, Method and Content Type. Configure the Body, Headers and Parameters required by the token API, using Credential values where appropriate.

Select HTTP Response and model returned fields such as access_token, refresh_token and the lifetime value, where supplied. Review the response policy.

Open the following Target Action and map those values back to the intended Credential fields. Check units before mapping a lifetime: a value returned in seconds must not be stored unchanged in a field measured in minutes.

HTTP Request and HTTP Response must remain consecutive, with the token-writing Target afterwards. See Configure a Credential Payload.

Attach the Credential to a business Payload

Open the consuming Outbound Payload and select HTTP Request → Request Settings. Choose the Bearer Token Credential and save the section.

Avoid adding a duplicate Authorization header. The business Payload should concentrate on its API request while the Credential supplies authentication.

Verify refresh and consumption

Run a controlled token refresh, then inspect the new Job’s request, response and Target output. Confirm the Credential’s Access Token Last Updated, expiry and token state reflect the result.

Run a controlled business request that uses the Credential and confirm the API accepts it. Investigate refresh failures separately from failures in the business request.

Jobs and exports can contain sensitive values. Redact tokens when sharing evidence; an export preview can mask secrets while copied or downloaded configuration retains their original values.

Did this answer your question?