Token getting process

This thread is now closed to new comments.
Some of the links and information provided in this thread may no longer be available or relevant.
If you have a question please start a new post.
The_Doc
Ultimate Partner
1,537 Posts
Ultimate Partner
Australia
Ultimate Partner

1,537Posts

235Kudos

162Solutions

Token getting process

Hi MYOB

 

Steven on the general forum mentioned there was (is) changes happening in the logon process of opening an online MYOB file 

 

i.e. that the pasword field now is only visible after you enter an email and I assume it gets checked for authenticity - and you are offered a password logon field if the email is registered?

 

Steven did say  that there was on-going changes in security procedures being developed?

 

Can you confirm or at least give some sort of heads up whether this will affect/change the current procedure for an API access to an online file.

 

i.e. 

 

1. establish a connection with a legitimate authenitcated logon (which requires a manual 2FA) process - fully manual (and for security reasons cannot be automated)

 

2. Once the manual process is successful - an Access Code is issued (life = 20 minutes) 

 

3. Access Code exchanged for Access Token (life = 20 minutes)  and a Refresh Token (Life = 7 days)

 

4. The Access Token is then used along with the file administrator password to access the data in the file via the API

5. The process can continue automatically (without further manual intervention) - so long as your Access Token is current (done by essentially always using the Refresh Token to get a new Access Token) 

 

Can you confirm this procedure will remain or is MYOB in the process of changing this?

 

The Doc

1 REPLY 1
Hannah_B
MYOB Moderator
142 Posts
MYOB Moderator
Australia
MYOB Moderator

142Posts

33Kudos

25Solutions

Re: Token getting process

Hi @The_Doc,

 

Thanks for reaching out. Yes that is correct, changes have been made to the login window of the AccountRight company file however via the API there is no change. Keep in mind the user setting option from the UI under Setup >> User Access >> Link My.myob, will still need to be left unticked so the CFtoken header is required. 

 

Yes, the process will remain the same as far as we have been advised. If there are any changes to the API this will be communicated to the community. 

 

Let us know if you have any questions, 

 

 

 


Thanks,
@Hannah_B


MYOB API Specialist


MYOB API Support Centre|MYOB App Marketplace|MYOB AccountRight API Endpoint Doc's



Did my answer help?


Mark it as a Solution

Didn't find your answer here?

Try using advanced search to find a post more easily Advanced Search
or
Get the conversation started and make a new post Start a Post