Accessing Protected APIs
~3 minWhen your app needs to call a backend API that requires authentication, use `ThunderIDClient.getAccessToken()` to retrieve a valid access token and attach it as a Bearer token to your requests. The SDK automatically refreshes the token if it has expired.
Accessing Protected APIs
Using URLSession
The following example calls a protected API endpoint using the standard `URLSession`:
func fetchProtectedResource(state: ThunderIDState) async throws -> Data {let token = try await state.client.getAccessToken()var request = URLRequest(url: URL(string: "https://localhost:8090/api/resource")!)request.setValue("Bearer \(token)", forHTTPHeaderField: "Authorization")request.setValue("application/json", forHTTPHeaderField: "Accept")let (data, response) = try await URLSession.shared.data(for: request)guard let httpResponse = response as? HTTPURLResponse,(200..<300).contains(httpResponse.statusCode) else {throw URLError(.badServerResponse)}return data}
Token Refresh
`getAccessToken()` refreshes the access token automatically when it is expired, as long as a valid refresh token is available. You do not need to handle refresh manually. If the refresh token is also expired, `getAccessToken()` throws `IAMError` with code `.sessionExpired`. Handle this by signing the user out:
do {let token = try await state.client.getAccessToken()// use token} catch let error as IAMError where error.code == .sessionExpired {_ = try? await state.client.signOut()await state.refresh()} catch {print("Unexpected error: \(error)")}
Using Alamofire
If your project uses [Alamofire](https://github.com/Alamofire/Alamofire), create a request interceptor that injects the access token:
final class ThunderIDRequestInterceptor: RequestInterceptor {let state: ThunderIDStateinit(state: ThunderIDState) {self.state = state}func adapt(_ urlRequest: URLRequest,for session: Session,completion: @escaping (Result<URLRequest, Error>) -> Void) {Task {do {let token = try await state.client.getAccessToken()var request = urlRequestrequest.setValue("Bearer \(token)", forHTTPHeaderField: "Authorization")completion(.success(request))} catch {completion(.failure(error))}}}}