> For the complete documentation index, see [llms.txt](https://docs.extrahorizon.com/extrahorizon/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.extrahorizon.com/extrahorizon/services/access-management/auth-service/oauth1.md).

# OAuth1

## Grants

### Password grant

The Password Grant accepts your username and password, then returns an Access Token and a Refresh token. As mentioned before the Access Token can be used to authenticate API requests.

See also the [Password Policy User Service setting ](/extrahorizon/services/access-management/user-service/configuration.md#password-policy)for more information about the password format and login attempts.

{% tabs %}
{% tab title="JavaScript" %}

```javascript
await exh.auth.authenticate({
    email:'john.doe@example.com',
    password:'myPassword1234'
});
```

{% endtab %}
{% endtabs %}

{% hint style="warning" %}
Note that in case this user has MFA enabled this function will throw a `MfaRequiredError`. With the information in the error you can follow the [MFA Grant](#mfa-grant) to complete the authentication.
{% endhint %}

### MFA Grant

When MFA is enabled for a user and you try to authenticate using the password grant you will receive a `MfaRequiredError` . You can catch the error and use the MFA Grant to complete the authentication.

{% tabs %}
{% tab title="JavaScript" %}

```javascript
try {
  await exh.auth.authenticate({
    password: '',
    email: '',
  });
} catch (error) {
  if (error instanceof MfaRequiredError) {
    const mfaToken = error.mfa.token;
    
    const mfaMethods = error.mfa.methods;
    // Your logic to request which method the user want to use in case of multiple methods
    const methodId = mfaMethods[0].id;

    await exh.auth.confirmMfa({
      token: mfaToken,
      methodId: methodId,
      code: '', // code from ie. Google Authenticator
    });
  }
  // handle other possible authentication errors
}
```

{% endtab %}
{% endtabs %}

### SSO Token Grant

You can exchange an SSO token generated by application for access tokens that can be used by another application. This way you can implement a single sign on flow between e.g. mobile and web.

{% tabs %}
{% tab title="JavaScript" %}

```javascript
await exh.auth.oauth1.consumeSsoToken("{ssoTokenHere}");
```

{% endtab %}
{% endtabs %}

## Tokens

### Retrieve a list of active tokens

{% tabs %}
{% tab title="JavaScript" %}

```javascript
await exh.auth.oauth1.tokens.find({
  rql: // Optional RQL
});
```

{% endtab %}
{% endtabs %}

### Revoking tokens

{% tabs %}
{% tab title="JavaScript" %}

```javascript
await exh.auth.oauth1.tokens.remove(tokenId);
```

{% endtab %}
{% endtabs %}

## SSO

### Generate SSO Tokens

You can create a single use SSO token. Another client can consume such a token and exchange it for an authorization.

{% tabs %}
{% tab title="JavaScript" %}

```javascript
await exh.auth.oauth1.generateSsoToken();
```

{% endtab %}
{% endtabs %}
