PayFit AccessToken

PayFit AccessToken

Certified

Exchange a PayFit authorization code

Exchanges an OAuth 2.0 authorization code at POST https://oauth.payfit.com/token using application/x-www-form-urlencoded. No API key is sent. The access token is valid for the company that approved the integration. Kestra encrypts the access token output only when kestra.encryption.secret-key is configured. Without that key, the execution output contains the token in clear text.

yaml
type: io.kestra.plugin.payfit.auth.AccessToken

Exchange a partner authorization code

yaml
id: payfit_access_token
namespace: company.team

tasks:
  - id: token
    type: io.kestra.plugin.payfit.auth.AccessToken
    clientId: "{{ secret('PAYFIT_CLIENT_ID') }}"
    clientSecret: "{{ secret('PAYFIT_CLIENT_SECRET') }}"
    code: "{{ inputs.code }}"
    redirectUri: "https://example.com/payfit/callback"
Properties

OAuth client id

OAuth client secret

Authorization code returned to the redirect URI

Redirect URI used when the authorization code was issued

Defaultauthorization_code

OAuth grant type. Defaults to authorization_code

Defaulthttps://oauth.payfit.com

OAuth base URL. Defaults to https://oauth.payfit.com

HTTP client options

Definitions
allowFailedbooleanstring
Defaultfalse

If true, allow a failed response code (response code >= 400)

allowedResponseCodesarray
SubTypeinteger

List of response code allowed for this request

auth

The authentication to use.

type*object
passwordstring

The password for HTTP basic authentication.

usernamestring

The username for HTTP basic authentication.

type*object
tokenstring

The token for bearer token authentication.

type*object
passwordstring

The password for HTTP Digest authentication.

usernamestring

The username for HTTP Digest authentication.

defaultCharsetstring
DefaultUTF-8

The default charset for the request.

enabledTcpExtendedKeepAlivebooleanstring
Defaulttrue

Whether to enable TCP Keep-Alive extended socket options (TCP_KEEPIDLE, TCP_KEEPINTERVAL, TCP_KEEPCOUNT).

Set to false when running on Windows workers, as these extended socket options are not supported by the Windows JDK and will cause connection failures.

followRedirectsbooleanstring
Defaulttrue

Whether redirects should be followed automatically.

logsarray
SubTypestring
Possible Values
REQUEST_HEADERSREQUEST_BODYRESPONSE_HEADERSRESPONSE_BODY

The enabled log.

proxy

The proxy configuration.

addressstring

The address of the proxy server.

passwordstring

The password for proxy authentication.

portintegerstring

The port of the proxy server.

typestring
DefaultDIRECT
Possible Values
DIRECTHTTPSOCKS

The type of proxy to use.

usernamestring

The username for proxy authentication.

ssl

The SSL request options

insecureTrustAllCertificatesbooleanstring

Whether to disable checking of the remote SSL certificate.

Only applies if no trust store is configured. Note: This makes the SSL connection insecure and should only be used for testing. If you are using a self-signed certificate, set up a trust store instead.

timeout

The timeout configuration.

connectTimeoutstring

The time allowed to establish a connection to the server before failing.

readIdleTimeoutstring
DefaultPT5M

The time allowed for a read connection to remain idle before closing it.

Access token to send as a bearer token on Partner API requests, encrypted in the execution outputs

Company id, when PayFit returns one with the token

Lifetime in seconds, when PayFit returns expires_in

Granted scopes

Token type