Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium

A SOC engineer is building a custom integration in Cortex XSOAR to interact with a proprietary security tool. The tool's API uses a unique authentication mechanism where a session token is obtained via a login endpoint and then must be included in a custom HTTP header for all subsequent API calls. This token expires every 30 minutes. Which integration feature is best suited to manage this token lifecycle automatically?

  1. AImplementing a custom token refresh logic within the `Client` class.
  2. BUsing the `demisto.persistent()` function to store the token.
  3. CStoring the token as an encrypted integration parameter.
  4. DHardcoding the token and manually updating it every 30 minutes.
Show answer & explanation

Correct answer: A. Implementing a custom token refresh logic within the `Client` class.

Implementing custom token refresh logic within the integration's `Client` class allows for automatic acquisition and renewal of the session token. This ensures that subsequent API calls always use a valid token without manual intervention.

Why the other options are wrong

  • B. `demisto.persistent()` stores data persistently but doesn't inherently manage token refresh logic or expiration checks.
  • C. Storing it as an encrypted parameter doesn't solve the problem of automatic refresh and would still require manual updates.
  • D. Hardcoding and manual updates are highly inefficient and prone to errors for frequently expiring tokens.

Custom Token Refresh Logic

Code implemented within a custom integration's `Client` class to automatically acquire, store, and refresh authentication tokens before they expire, ensuring continuous access to external APIs.

  • Handles token acquisition and renewal.
  • Typically implemented in the `Client` class.
  • Ensures valid tokens for all API calls.

Memory trick: Refreshing tokens keeps the connection flowing smoothly.

More Integrations questions