How do I authorise a cron job php file to access Xero?

Viewed 1128

I am migrating to Xero and want to set an invoicing process to run once a month at a specific time using a cron job, I can get the cron job to fire and I have set up a php page based on https://github.com/XeroAPI/xero-php-oauth2-app which I can run manually and it works perfectly.

I've also used https://github.com/XeroAPI/xoauth to retrieve the tokens and store them in the keychain, I can see that they are there.

I've got a bit lost where xoauth says "Piping the access_token, id_token and refresh_token to stdout, so you can use them in a script workflow"

I'm hoping someone has done something similar and can point me in the right direction or even better give me an example as I can't find one online.

I assume I am missing a link between the 2 examples which transfers the token values.

When the cron runs I get the following error

'Fatal error: Uncaught BadMethodCallException: Required parameter not passed: "refresh_token" in /Applications/MAMP/htdocs/vendor/league/oauth2-client/src/Tool/RequiredParameterTrait.php:35'

which is not really a surprise as I'm not giving it a refresh_token as far as I can see.

I am using localhost on a Mac as a development environment.

I have seen a number of questions related to this from more experienced developers but no answers.

Thanks Gordon

1 Answers

thanks for your question. We have gotten this one a lot so I used this as the base for a XeroAPI community-corner video that I will share back here soon that walks through getting access/refresh tokens from xoauth, making api calls, and refreshing to get a new token set.

Answer

What you want to do is after you generate the access token with the xoauth repo. In your PHP script - plug in the access_token & xero-tenant-id (as 2 headers in your api call).

Authorization: "Bearer " + access_token
xero-tenant-id: tenantId

Ensure the API call returns your data. Then create a function in your script that does the following before future API calls

  1. Refreshes for a new token_set
  2. Saves new token_set to a DB or static file
  3. Use that token_set 'access_token' to make your Invoice API call
  4. Repeat step (1-3) at least once every 60 days

NOTE: you will need some kind of persistence to store the continually refreshed token_set.

Hope this clarifies it for you. I will post back the video for an in depth walkthrough asap.

OAuth2.0 Background:

Essentially our move to simplify and standardize our API authentication came with some challenges in how to setup longstanding API connections for use cases that didn’t need to onboard an increasing number of new users. For instance, a lot of small businesses and accounting firms setup custom processes to batch import/export invoices.

The use case often did not have the need for an application user interface, so standing one up just to get a valid access token was a lot of extra work if the integration only needed to connect to single ‘admin’ type user for a specific Xero Organisation.

Related