A security analyst is developing a custom integration in Cortex XSOAR that interacts with a threat intelligence platform. The platform's API requires a bearer token for authentication, which expires every 60 minutes. The integration needs to automatically refresh this token before it expires or when an authentication error occurs, without requiring manual intervention. How should the integration handle this token refresh mechanism?
- ARequire the user to manually update the token in the integration instance parameters every 60 minutes.
- BImplement logic within the `BaseClient` (e.g., in `_http_request`) to check token expiry or handle authentication errors, then refresh and retry.
- CStore the token in the incident context and refresh it using a playbook task every 50 minutes.
- DImplement a cron job on the XSOAR server to periodically call a token refresh command.
Show answer & explanationAnswer & explanation
Correct answer: B. Implement logic within the `BaseClient` (e.g., in `_http_request`) to check token expiry or handle authentication errors, then refresh and retry.
The most robust and automated way to handle expiring tokens is to embed the refresh logic within the `BaseClient`'s `_http_request` method or a similar wrapper. This allows the integration to proactively check for token expiry or react to authentication failures, refresh the token, and automatically retry the original request, ensuring seamless operation.
Why the other options are wrong
- A. Manual token updates are not scalable or automated, defeating the purpose of an integration.
- C. While playbooks can manage tokens, integrating the refresh directly into the `BaseClient` ensures that *any* command using that client benefits from the automatic refresh, and it handles immediate retry upon failure, which a playbook might not do as gracefully.
- D. Using external cron jobs is not the idiomatic XSOAR way for integration-specific logic and can introduce management overhead and security concerns.
Automated Token Refresh (Integration)
Automated token refresh in a Cortex XSOAR integration involves implementing logic, typically within the `BaseClient`'s request handling, to detect token expiry or authentication failures, acquire a new token, and automatically retry the original request without manual intervention.
- Crucial for long-running integrations with expiring tokens.
- Often implemented by overriding `_http_request` or a similar method.
- Enhances reliability and reduces operational overhead.
Memory trick: BaseClient Builds Better Bearer Belief.