Implement getUserData changes
Get Access Token API
Appstore IAP provides the Get Access Token REST API for you to obtain an access token. This section describes the request, response, and errors.Access token request
After the app receives a response to with a valid authorization code, it can use that code to obtain an access token. With an access token, the client can read a customer profile. The Get Access Token API must use a POST request rather than a GET request, as shown in the following example.| Request parameter | Description |
|---|---|
grant_type | Required. The type of access grant requested. Must be authorization_code. |
code | Required. The authorization code returned by the method. |
client_id | Required. The client identifier. |
client_secret | Required. The secret value assigned to the client during registration. Don’t use the client secret in browser-based apps because client secrets can’t be reliably stored on web pages. |
Access token response
To access customer data, you must provide an access token to the Appstore IAP Get User Profile API. An access token is an alphanumeric code 350 characters or more in length, with a maximum size of 2048 bytes. Access tokens begin with the charactersAtza|.
Response parameters are encoded using the application/json media type. For more information, see RFC4627. The following is an example response from an access token request.
| Response parameter | Description |
|---|---|
access_token | The access token for the user account. Maximum size of 2048 bytes. |
token_type | The type of token returned. Value is bearer. |
expires_in | The number of seconds before the access token becomes invalid. |
refresh_token | A refresh token that can be used to request a new access token. Maximum size of 2048 bytes. |
Access token errors
For some errors, the authorization service may return anHTTP 401 (Unauthorized) status code. This includes cases where the client passed the client_id and client_secret values in the authorization header and the client could not be authenticated.
The following table describes the error parameters in an unsuccessful response.
| Error parameter | Description |
|---|---|
error | An ASCII error code with an error code value. |
error_description | A human-readable ASCII string with information about the error, useful for client developers. |
request_id | ID associated to your access token request. |
error.
| Error code | Description |
|---|---|
invalid_request | The request is missing a required parameter, has an invalid value, or is otherwise improperly formed. |
invalid_client | The client authentication failed. This is used in cases when the authorization service does not return an HTTP 401 (Unauthorized) status code. |
invalid_grant | The authorization code is invalid, expired, revoked, or was issued to a different client_id. |
unauthorized_client | The client is not authorized to use authorization codes. Can be caused by invalid code_verifier. |
unsupported_grant_type | The client specified the wrong token_type. |
ServerError | The server encountered a runtime error. |
Get User Profile API
Appstore IAP provides the Get User Profile REST API to get user profile data. This section describes the request, response, and errors.User profile request
To access authorized user profile data, use the Get User Profile API to submit the access token to the Appstore. The Get User Profile API uses an HTTPS GET request and takes the access token that you received from the Get Access Token API as it’s only parameter. The following example shows a GET request to obtain user profile data.| Request parameter | Description |
|---|---|
access_token | Required. The access token received from the Get Access Token API. |
User profile response
If your access token is valid, you receive the customer’s profile data as an HTTP response in JSON, as shown in this example.| HTTP status code | Status message | Description |
|---|---|---|
| 200 | Success | The request was successful. |
| 400 | invalid_request | The request is missing a required parameter or otherwise malformed. |
| 400 | invalid_token | The access token provided is expired, revoked, malformed, or invalid for other reasons. |
| 401 | insufficient_scope | The access token provided does not have access to the required scope. |
| 500 | ServerError | The server encountered a runtime error. |
Best practices for account setup
Follow these best practices for setting up customer accounts.- If
UserProfileAccessConsentStatushas the valueCONSENTEDin the , do the following:- Fetch the user information from the Appstore IAP Get User Profile API. Use this information to create a login account with a temporary password. Sign the customer in to the app without requesting a password reset or additional details from the customer.
- Later, ask the customer to reset the password through email.
- If
UserProfileAccessConsentStatusisUNAVAILABLE, use the default app sign-up experience for the customer.

