Using sessionToken how can get access_token and id_token

Hi nate.barbettini,

Before going to solve this issue one more question i have.

Regarding the logout api

  1. https://dev-255595.oktapreview.com/api/v1/authn to get the session_id

  2. https://dev-255595.oktapreview.com/oauth2/v1/authorize?client_id=0oadeindnmS6oN5rN0h7&redirect_uri=http%3A%2F%2F127.0.0.1%3A8000%2Fauthorization-code%2Fcallback&response_type=code&response_mode=query&state=FkSgPf7a6gRQcXt9IBFy0fy5foXIFUS6pYPB6aQhvHpSACdFxh1QJzgBTGHvhzv7&nonce=yG4cCBUwuRBob89woR8YuXeZdXelgk2jlMkZDthZyEdU27tfGHBsuZxrL98ybRW5&display=page&sessionToken=20111f6upKTDrSIBDI17c_C-f-s0Ck28SDBYG6eKEc8fn4nZihxkysH&scope=openid%20profile%20email

query parameter: client_id=0oadeindnmS6oN5rN0h7&redirect_uri=http%3A%2F%2F127.0.0.1%3A8000%2Fauthorization-code%2Fcallback&response_type=code&response_mode=query&state=FkSgPf7a6gRQcXt9IBFy0fy5foXIFUS6pYPB6aQhvHpSACdFxh1QJzgBTGHvhzv7&nonce=yG4cCBUwuRBob89woR8YuXeZdXelgk2jlMkZDthZyEdU27tfGHBsuZxrL98ybRW5&display=page&sessionToken=20111f6upKTDrSIBDI17c_C-f-s0Ck28SDBYG6eKEc8fn4nZihxkysH&scope=openid%20profile%20email

  1. http://127.0.0.1:8000/authorization-code/callback?code=th40dAqyHSzO8moJxgu1&state=FkSgPf7a6gRQcXt9IBFy0fy5foXIFUS6pYPB6aQhvHpSACdFxh1QJzgBTGHvhzv7

  2. Using the code generated the access_token and id_token

{‘access_token’: u’eyJraWQiOiJFdHZUWU0tajZRREp3OW5qUTFPMFpGV1hWNGtUbHlVSV9fdm5mSTNpOUU4IiwiYWxnIjoiUlMyNTYifQ.eyJ2ZXIiOjEsImp0aSI6IkFULk9tcUM2UXNOVW1lTHlHSWJkSE5WZXNCeWZYLXkzTjlaemh6U21UejlicHMiLCJpc3MiOiJodHRwczovL2Rldi0yNTU1OTUub2t0YXByZXZpZXcuY29tIiwiYXVkIjoiaHR0cHM6Ly9kZXYtMjU1NTk1Lm9rdGFwcmV2aWV3LmNvbSIsInN1YiI6ImJwYXR0dXNhbXlAY29udml2YS5jb20iLCJpYXQiOjE1MjIzMDMwMzksImV4cCI6MTUyMjMwNjYzOSwiY2lkIjoiMG9hZGVpbmRubVM2b041ck4waDciLCJ1aWQiOiIwMHVkY2VxMHh3MEFvb2pINjBoNyIsInNjcCI6WyJvcGVuaWQiLCJlbWFpbCIsInByb2ZpbGUiXX0.GQRsegWIXx5ieOneqQrP52lSlqX4LyDs17zC9bViCpuI8Y1Y-dJ5-5sILavEy-G9mVuQoKyOrQjulOg9x6VbpCeuzquvSKACaCllHZ9wmezBeDWb8WdDVwbboN-BzBVjr3potoUCTg-AK_-Jw66LuqsLbsxpvxC9urjfkPATDBHkK5wc0-8kid9GUZo5J9zU9jzy7PXasq2q0JJEbYif08W9_ofncTMm40BcR-rhWufMmv6CNx2jE_f-XFgTwdVDE-HWjuj5OPfmmhV2jP6jWWoEnFuFxpjx5Lkuk2QBui-6PNUXk4XjOezj1gRI7tgmFLogE-wKLvzPuiq8amuLgg’, ‘id_token’: u’eyJraWQiOiJFRHA0TzBNa2xJM2xKc2ZWd01ILXRkczhPZnFyclJJeDBTNnk0cHBib1U4IiwiYWxnIjoiUlMyNTYifQ.eyJzdWIiOiIwMHVkY2VxMHh3MEFvb2pINjBoNyIsIm5hbWUiOiJCQUxBIiwiZW1haWwiOiJicGF0dHVzYW15QGNvbnZpdmEuY29tIiwidmVyIjoxLCJpc3MiOiJodHRwczovL2Rldi0yNTU1OTUub2t0YXByZXZpZXcuY29tIiwiYXVkIjoiMG9hZGVpbmRubVM2b041ck4waDciLCJpYXQiOjE1MjIzMDMwMzksImV4cCI6MTUyMjMwNjYzOSwianRpIjoiSUQuMElIeDRldXlHVXFjX1VHUjJhZVV3M2FvaDNYMkFpTW93eUhRcmJLYWxQYyIsImFtciI6WyJwd2QiXSwiaWRwIjoiMDBvZGNlcTB2ZDl1eGJVUjMwaDciLCJub25jZSI6InlHNGNDQlV3dVJCb2I4OXdvUjhZdVhlWmRYZWxnazJqbE1rWkR0aFp5RWRVMjd0ZkdIQnN1WnhyTDk4eWJSVzUiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJicGF0dHVzYW15QGNvbnZpdmEuY29tIiwiYXV0aF90aW1lIjoxNTIyMzAzMDM2LCJhdF9oYXNoIjoiM3FoRWdHVFdZTzgwcGU4R2ZXVGxGdyJ9.Xrhjf5GhPfrg_NpZUXLs0L-mQFCmmwbAsju2guHOvItwcRayOBSKvc4Y0sq_UyxdVziTfo-d_AfbBU1yxAYFWenyChU3OseXQQziHuyYX08NCveBShs7WjxJKp5Cg-wtrrqTrZ3p3NU2qZqrSRhkWPUrt5dnEfqthH-widN_KiZWy108hZjTWCR5ZcRPHnraYixApsMpwkoYiOUX_IxUofUQBc1UVFqTE4atmNbtgVZXyg18m_kY365EmIUwGWWnzTY0BpL0-_AI4dk1CnTUB4Ak6ldfdvQnfJQYDxls8jx1dJWaWSJXvTh-hkVyTtkJOw9uNSL84cajFyhRpLC8pw’}

  1. using the id_token have to call logout api.

https://dev-255595.oktapreview.com/oauth2/v1/logout?post_logout_redirect_uri=http%3A%2F%2F127.0.0.1%3A8000%2Flogin&
id_token_hint=eyJraWQiOiJFRHA0TzBNa2xJM2xKc2ZWd01ILXRkczhPZnFyclJJeDBTNnk0cHBib1U4IiwiYWxnIjoiUlMyNTYifQ.eyJzdWIiOiIwMHVkY2VxMHh3MEFvb2pINjBoNyIsIm5hbWUiOiJCQUxBIiwiZW1haWwiOiJicGF0dHVzYW15QGNvbnZpdmEuY29tIiwidmVyIjoxLCJpc3MiOiJodHRwczovL2Rldi0yNTU1OTUub2t0YXByZXZpZXcuY29tIiwiYXVkIjoiMG9hZGVpbmRubVM2b041ck4waDciLCJpYXQiOjE1MjIzMDMwMzksImV4cCI6MTUyMjMwNjYzOSwianRpIjoiSUQuMElIeDRldXlHVXFjX1VHUjJhZVV3M2FvaDNYMkFpTW93eUhRcmJLYWxQYyIsImFtciI6WyJwd2QiXSwiaWRwIjoiMDBvZGNlcTB2ZDl1eGJVUjMwaDciLCJub25jZSI6InlHNGNDQlV3dVJCb2I4OXdvUjhZdVhlWmRYZWxnazJqbE1rWkR0aFp5RWRVMjd0ZkdIQnN1WnhyTDk4eWJSVzUiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJicGF0dHVzYW15QGNvbnZpdmEuY29tIiwiYXV0aF90aW1lIjoxNTIyMzAzMDM2LCJhdF9oYXNoIjoiM3FoRWdHVFdZTzgwcGU4R2ZXVGxGdyJ9.Xrhjf5GhPfrg_NpZUXLs0L-mQFCmmwbAsju2guHOvItwcRayOBSKvc4Y0sq_UyxdVziTfo-d_AfbBU1yxAYFWenyChU3OseXQQziHuyYX08NCveBShs7WjxJKp5Cg-wtrrqTrZ3p3NU2qZqrSRhkWPUrt5dnEfqthH-widN_KiZWy108hZjTWCR5ZcRPHnraYixApsMpwkoYiOUX_IxUofUQBc1UVFqTE4atmNbtgVZXyg18m_kY365EmIUwGWWnzTY0BpL0-_AI4dk1CnTUB4Ak6ldfdvQnfJQYDxls8jx1dJWaWSJXvTh-hkVyTtkJOw9uNSL84cajFyhRpLC8pw&
state=FkSgPf7a6gRQcXt9IBFy0fy5foXIFUS6pYPB6aQhvHpSACdFxh1QJzgBTGHvhzv7

Here the logout api is not working 403 forbidden error getting