> This page is for Piattaforma, version Versione precedente.
> For other versions, use one of these documentation indexes:
> - V4 (default): https://next.developer.frame.io/platform/v4/llms.txt
> - V4 sperimentale: https://next.developer.frame.io/platform/v4-experimental/llms.txt
> - Versione precedente: https://next.developer.frame.io/platform/v2/llms.txt

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://next.developer.frame.io/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://next.developer.frame.io/_mcp/server.

# Aggiornamento dei token OAuth 2

<Warning title="Questa guida presuppone che tu abbia già creato un'app OAuth2">
  Se non l'hai fatto, consulta [questa](/oauth-2-applications/building-an-oauth-2-app) guida e torna qui una volta acquisiti `access_token` e `refresh_token` da una concessione di credenziali OAuth 2 riuscita.
</Warning>


## Nozioni di base sull'aggiornamento dei token

Supponendo che tu abbia incluso l'ambito ***offline*** nella richiesta di credenziali OAuth2.0, l'autenticazione riuscita tramite l'applicazione degli account di Frame.io restituirà un payload simile al seguente:

```json
{
  "access_token":"BEARER_TOKEN",
  "expires_in":3600,
  "refresh_token":"REFRESH_TOKEN",
  "scope":"account.read offline",
  "token_type":"bearer"
}
```

`access_token` è un token bearer che può essere utilizzato per agire per conto dell'utente autenticato; scadrà dopo 3600 secondi (un'ora); dopodiché il `refresh_token` potrà essere utilizzato per recuperare un nuovo `access_token`. Il token di aggiornamento scadrà dopo 30 giorni, trascorsi i quali l'utente dovrà eseguire di nuovo l'accesso da zero, producendo una nuova coppia di token di accesso e aggiornamento e così via. Se non richiedi esplicitamente l'ambito *offline*, non riceverai un `refresh_token`, perciò dopo un'ora dovrai riautenticare completamente l'utente.

### Acquisizione del token di aggiornamento in caso di autenticazione riuscita

Ovviamente, non puoi utilizzare un `refresh_token` che non hai, quindi nella tua app devi fare quanto segue:
* Richiedi l'ambito **offline**
* Acquisisci il `refresh_token` restituito in un callback riuscito.

Per comodità, qui è riprodotto il callback delle nostre [guide per le app OAuth 2](/oauth-2-applications/building-an-oauth-2-app), con una chiamata `os` per memorizzare il token di aggiornamento. Tieni presente che vengono forniti due esempi: uno con PKCE configurato (non include l'intestazione di autenticazione di base) e uno senza (include l'intestazione di autenticazione di base).

### Senza PKCE




**`Python`**

```python title="Python"
def callback():
  # Where `request` refers to our initial call to the auth URL
  state = request.args.get('state')
  scope = request.args.get('scope')
  code = request.args.get('code')
  error = request.args.get('error')

  if error:
    return "Error: " + error

  # Set up for client authorization and set up the data you need to send.
  client_auth = requests.auth.HTTPBasicAuth(CLIENT_ID, CLIENT_SECRET)

  post_data = {
    "grant_type": "authorization_code",
    "code": code,
    "redirect_uri": REDIRECT_URI,
    "state": state,
    "scope": SCOPE
  }

  # Send a POST request with the data you need to receive an access token. 
  response = requests.post(TOKEN, auth=client_auth, data=post_data)    
	# Stash the refresh token for later
  os.environ['REFRESH_TOKEN'] = response.json()["refresh_token"]

  return response.text
```





### Con PKCE




**`Python`**

```python title="Python"
def callback():
  # Where `request` refers to our initial call to the auth URL
  state = request.args.get('state')
  scope = request.args.get('scope')
  code = request.args.get('code')
  error = request.args.get('error')

  if error:
    return "Error: " + error

  # If using PKCE, you must include the CLIENT_ID in your request body  
  post_data = {
    "grant_type": "authorization_code",
    "code": code,
    "redirect_uri": REDIRECT_URI,
    "state": state,
    "scope": SCOPE
    "client_id": CLIENT_ID 
  }

  # Send a POST request with the data you need to receive an access token.
  # If using PKCE, use the below request with no auth
  response = requests.post(TOKEN_URL, data=post_data)
  # Stash the refresh token for later
  os.environ['REFRESH_TOKEN'] = response.json()["refresh_token"]

  return response.text
```




## Esecuzione di un aggiornamento




L'aggiornamento stesso è una singola chiamata all'URL del token di Frame.io:



* Metodo: POST
* URL: **https://applications.frame.io/oauth2/token**
* `Content-Type`: *application/x-www-form-urlencoded*




Un aggiornamento include sempre almeno i seguenti tre attributi nei dati del modulo:



* `grant_type`: *refresh_token*
* `scope`: &lt;scopes&gt;
* `refresh_token`: &lt;refresh_token&gt;

Se usi PKCE, devi includere il `client_id` dell'app nei dati di questo modulo; altrimenti, devi includere un'intestazione di autenticazione Basic con il `client_id` e il `client_secret` dell'app come nome utente e password, rispettivamente.

### Senza PKCE

In modo simile al [callback di autenticazione iniziale](/oauth-2-applications/building-an-oauth-2-app#the-callback) senza PKCE, questo aggiornamento standard prevede la specifica del `client_id` e del `client_secret` come nome utente e password in un'intestazione di autenticazione Basic.

**`Python`**

```python title="Python"
def refresh():
  # Fetch the refresh token, assuming we have it
  REFRESH_TOKEN = os.environ.get('REFRESH_TOKEN')

  client_auth = requests.auth.HTTPBasicAuth(CLIENT_ID,CLIENT_SECRET)
  post_data = {
    "grant_type": "refresh_token",
    "scope": SCOPE,
    "refresh_token": REFRESH_TOKEN
    # if using PKCE, you will need to include your client_id as below
    # "client_id": CLIENT_ID 
  }

  response = requests.post(TOKEN_URL, auth=client_auth, data=post_data)
  # Catch + stash a new Refresh Token
  os.environ['REFRESH_TOKEN'] = response.json()["refresh_token"]

  return response.text
```




### Con PKCE

Ancora una volta, stiamo seguendo le regole del ciclo `/callback` iniziale:
* Non includiamo un'intestazione `Authorization`
* Dobbiamo includere il `client_id` nel payload




**`Python`**

```python title="Python"
def refresh():
  # Fetch the refresh token, assuming we have it
  REFRESH_TOKEN = os.environ.get('REFRESH_TOKEN')

  post_data = {
    "grant_type": "refresh_token",
    "scope": SCOPE,
    "refresh_token": REFRESH_TOKEN
    "client_id": CLIENT_ID 
  }

  response = requests.post(TOKEN_URL, data=post_data)
  # Catch + stash a new Refresh Token
  os.environ['REFRESH_TOKEN'] = response.json()["refresh_token"]

  return response.text
```




Complimenti! Ora puoi gestire l'intero ciclo di vita dei token di un'applicazione client OAuth2.0.