Where to hold 2 access tokens for 2 different APIs?

Viewed 35

We're building a web frontend which authenticates users through Auth0 getting back access token, and a backend middleware which connects to a 3rd party API which holds the business logic. (flow is web frontend -> middleware API -> 3rd party API)

3rd party API also returns access token per user during authentication process (it's not a M2M scenario because the API was built to serve frontends only), so effectively we will have 2 access tokens - one from Auth0 for middleware authorization (web frontend -> middleware API), and one for 3rd party API (middleware API -> 3rd party API).

I was thinking to hold both tokens on the device of the frontend app, and then propagate 3rd party access token in request headers to middleware API. This is because I want to make login, logout, refresh, etc atomic, I don't want to find myself in a situation where I have 1 access token on the frontend and the 2nd one in the middleware and then to keep them in sync.

Is this correct way to do it or is there a better way?

0 Answers
Related