A security engineer is developing a custom integration for Cortex XSOAR that interacts with a cloud-based security service. The service uses an API key that expires every 60 minutes and requires re-authentication to obtain a new one. To prevent integration failures, this API key needs to be automatically refreshed. How should the integration be designed to handle this token refresh mechanism MOST effectively?
- AImplement a scheduled task in Cortex XSOAR to call a refresh command every 55 minutes.
- BStore the API key in the integration instance parameters and manually update it every 60 minutes.
- CUse a long-lived API key provided by the cloud service that does not expire.
- DOverride the `_http_request` method in `BaseClient` to check token validity and refresh it if expired before each request.
Show answer & explanationAnswer & explanation
Correct answer: D. Override the `_http_request` method in `BaseClient` to check token validity and refresh it if expired before each request.
Overriding `_http_request` in `BaseClient` allows for pre-request logic. This is the ideal place to check the validity of the current API key/token and, if expired, call a refresh function to obtain a new one before proceeding with the actual API call. This ensures that every request is sent with a valid token, making the refresh mechanism transparent to individual command implementations.
Why the other options are wrong
- A. A scheduled task might refresh the token, but it doesn't guarantee the token is fresh *before* every single request, especially if requests are infrequent or bursty.
- B. Manual updates are not automated and will lead to failures.
- C. The scenario explicitly states the API key expires every 60 minutes, making a long-lived key not an option for this service.
Automated Token Refresh (Integration)
To handle frequently expiring API keys or tokens in a Cortex XSOAR custom integration, override the `_http_request` method in `BaseClient` to implement pre-request logic that checks token validity and refreshes it if needed before sending the actual API call.
- Ensures token is always valid for every request.
- Centralized and transparent refresh logic.
- Avoids manual intervention and separate schedulers.
Memory trick: Keep your 'key' fresh by checking it at the 'door' (http_request) every time.