Generating Tokens


Security and User Token Generation

After configuring the encryption settings on the Project API Settings page, Security Tokens and User Tokens can be generated and included in API requests. The token generation process consists of three distinct steps: token construction, encryption, and URL encoding.

Step 1: Construct the Plaintext Token

Tokens are initially created in plaintext using one of the supported formats:

  • XML
  • JSON
  • Form URL-encoded string

Sample Plaintext Security Token (XML)

<SecurityToken>
<SecurityContext>MySecurityContext</SecurityContext>
<ApplicationId>MyAppId</ApplicationId>
<ApplicationKey>MyAppKey</ApplicationKey>
<Timestamp>2023-03-08T14:15:53-08:00</Timestamp>
</SecurityToken>

Sample Plaintext User Token (XML)

<UserToken>
<UserName>admin</UserName>
<DisplayName>John Doe</DisplayName>
</UserToken>

Step 2: Encrypt and Base64 Encode the Token

Once the plaintext token has been created, it must be encrypted and Base64 encoded according to the encryption algorithm, key size, and encoding settings configured on the Project API Settings page.

Sample Security Token (Encrypted and Base64 Encoded)

C15OEgi932oPFmjdi6LH9w94vBOqvrdua4vKA+aAnoHe3E+0s06jIYs/Q5LxY2nC17qcpyCUZtbSJRf/PDx7AeScDnzuyUJDynvlwUJF8ebdHBFUvNWTFw4Oad8gbrmG4tC72zcj9BlBYpJv0DW5PXr4g/hnlEDg8Q8Wh6E1oO/6jLF8Y4FQRUej/LzYzNUnMZ5SLahHV54PdMtjU5VHfsvNuwRrCITJF9gmXmQtFD44wtvbYjAT0GhbXTwHp0XQ

Sample User Token (Encrypted and Base64 Encoded)

MkclD3MPKt5gQBcRDoqek5neDQjto+rXc7cneMpPoQV+JqL52gJt4K2e3vOmjf6RCBRrQUjYh4fdzD2qT6iYIrXrEX6OblTTmoxfhpvehOQU6NvEpzOPgkfUl8fMU3TV

Step 3: URL Encode the Token

Before a token can be passed as a parameter in an HTTP request, the encrypted value must be URL encoded to ensure special characters are transmitted correctly.

Security Token (Passed Using the XST Parameter)

C15OEgi932oPFmjdi6LH9w94vBOqvrdua4vKA%2BaAnoHe3E%2B0s06jIYs%2FQ5LxY2nC17qcpyCUZtbSJRf%2FPDx7AeScDnzuyUJDynvlwUJF8ebdHBFUvNWTFw4Oad8gbrmG4tC72zcj9BlBYpJv0DW5PXr4g%2FhnlEDg8Q8Wh6E1oO%2F6jLF8Y4FQRUej%2FLzYzNUnMZ5SLahHV54PdMtjU5VHfsvNuwRrCITJF9gmXmQtFD44wtvbYjAT0GhbXTwHp0XQ

User Token (Passed Using the XUT Parameter)

MkclD3MPKt5gQBcRDoqek5neDQjto%2BrXc7cneMpPoQV%2BJqL52gJt4K2e3vOmjf6RCBRrQUjYh4fdzD2qT6iYIrXrEX6OblTTmoxfhpvehOQU6NvEpzOPgkfUl8fMU3TV

Request Flow Summary

The complete token generation process can be summarized as follows:

Plaintext Token

Encrypt

Base64 Encode

URL Encode

Pass in API Request (XST / XUT)

Additional Information

For detailed information regarding token construction, encryption requirements, authentication flow, and implementation examples, refer to:

These sections provide comprehensive guidance on configuring and using XDOC's token-based authentication and secure user context mechanisms for API and UI integration scenarios.