# API with expiring access token

**URL:** <https://community.glideapps.com/t/api-with-expiring-access-token/76591>\
**Category:** Ask for Help\
**Created:** [September 24, 2024, 1:20pm UTC](https://community.glideapps.com/t/api-with-expiring-access-token/76591 "2024-09-24T13:20:15Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![PioneerTown](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/pioneertown/32/78768_2.png) [@PioneerTown](https://community.glideapps.com/u/PioneerTown)\
**Post date:** [September 24, 2024, 1:20pm UTC](https://community.glideapps.com/t/api-with-expiring-access-token/76591/1 "2024-09-24T13:20:15Z")

</div>

Hi there!

I need to create an integration for a customer with the [Guesty.com](http://Guesty.com) API.  
However, Guesty uses expiring access tokens. Which means you have to request a new acces token each 24h.

Is it possible to call this API with Glide apps?

> **[Authentication](https://open-api-docs.guesty.com/docs/authentication)**
>
> Generating an access token to authenticate Open API requests.

Thank you!

Nathan

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [September 24, 2024, 1:25pm UTC](https://community.glideapps.com/t/api-with-expiring-access-token/76591/2 "2024-09-24T13:25:51Z")

</div>

Yeah you can do that with a conditional (branching) action. Start by checking if the token is still valid. If is isn’t, make an API call to get a new token, wait until it arrives, and then make the second API call. If it isn’t, skip the token refresh and go ahead and make the call.

---

<div class="post-metadata">

**Author:** ![PioneerTown](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/pioneertown/32/78768_2.png) [@PioneerTown](https://community.glideapps.com/u/PioneerTown)\
**Post date:** [September 24, 2024, 1:25pm UTC](https://community.glideapps.com/t/api-with-expiring-access-token/76591/3 "2024-09-24T13:25:58Z")

</div>

I guess you would have to create one API call to get the access code and store the acces code in the database?

And one any action that needs info from the API check if it’s less than 1h from the expiration date of the current access code, if yes, call the API to request a new acces code and continue to call the API with the old access code.

The next API call will have the new access code.

The only pitfall in this is that you will need to store the access token in a publicly available way in the database…

---

<div class="post-metadata">

**Author:** ![PioneerTown](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/pioneertown/32/78768_2.png) [@PioneerTown](https://community.glideapps.com/u/PioneerTown)\
**Post date:** [September 24, 2024, 1:26pm UTC](https://community.glideapps.com/t/api-with-expiring-access-token/76591/4 "2024-09-24T13:26:35Z")

</div>

Exactly, but then you have to save the token in the database. Won’t this be a security issue?

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [September 24, 2024, 1:38pm UTC](https://community.glideapps.com/t/api-with-expiring-access-token/76591/5 "2024-09-24T13:38:50Z")

</div>

Yeah that’s a good point. Off the top of my head, the only way I can think around that is to delegate the API calls to something like Make, via a webhook.

I guess an alternative could be to request a new token with every execution, and then immediately clear it 🤷🏼‍♂️

---

<div class="post-metadata">

**Author:** ![PioneerTown](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/pioneertown/32/78768_2.png) [@PioneerTown](https://community.glideapps.com/u/PioneerTown)\
**Post date:** [September 24, 2024, 2:04pm UTC](https://community.glideapps.com/t/api-with-expiring-access-token/76591/6 "2024-09-24T14:04:10Z")

</div>

Clearing it immediately doesn’t work as there will be a limit on token request calls. Mitigating to another tool would work! Thanks for the help man! 😃

---

<div class="post-metadata">

**Author:** ![ThinhDinh](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/thinhdinh/32/49_2.png) [@ThinhDinh](https://community.glideapps.com/u/ThinhDinh)\
**Post date:** [September 24, 2024, 2:52pm UTC](https://community.glideapps.com/t/api-with-expiring-access-token/76591/7 "2024-09-24T14:52:25Z")

</div>

Maybe you can write the timestamp of when an access token is generated, and calculate their expiring time. When you make a call, if the expiring time is after now, proceed as usual, else generate a new token first before making the main call.

---

<div class="post-metadata">

**Author:** ![system](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/system/32/53398_2.png) [@system](https://community.glideapps.com/u/system)\
**Post date:** [October 1, 2024, 2:52pm UTC](https://community.glideapps.com/t/api-with-expiring-access-token/76591/8 "2024-10-01T14:52:46Z")

</div>

This topic was automatically closed 7 days after the last reply. New replies are no longer allowed.
