DevNet Associate (DEVASC) v1.0Understanding and Using APIsMedium

A developer is integrating a Python application with a Cisco DNA Center API, which uses OAuth 2.0 for authentication. After successfully obtaining an access token, the application attempts to make several API calls. It receives an HTTP 401 Unauthorized error after approximately 60 minutes of operation, despite the access token initially being valid. What is the most likely cause of this error?

  1. AThe API rate limit has been exceeded, leading to temporary denial of service.
  2. BThe API key being used has been revoked by the administrator.
  3. CThe access token has expired and needs to be refreshed or re-obtained.
  4. DThe application's network connectivity to the DNA Center API was temporarily lost.
Show answer & explanation

Correct answer: C. The access token has expired and needs to be refreshed or re-obtained.

OAuth 2.0 access tokens have a limited lifespan (often 1 hour or less for security reasons). An HTTP 401 Unauthorized error after a period of successful operation strongly indicates that the access token has expired. The application needs to handle this by using a refresh token or re-initiating the authorization flow to get a new access token.

Why the other options are wrong

  • A. Exceeding the API rate limit typically results in an HTTP 429 Too Many Requests error, not a 401 Unauthorized.
  • B. A revoked API key would likely cause immediate 401 errors, not after a period of successful operation.
  • D. Network connectivity issues would typically result in different errors (e.g., connection timed out), not a 401 Unauthorized.

OAuth 2.0 Token Expiration

OAuth 2.0 access tokens are designed with a limited lifespan for security. Once expired, they are no longer valid for accessing protected resources, leading to an 'Unauthorized' error, and require renewal, often via a refresh token.

  • Access tokens have a defined `expires_in` duration.
  • Expired tokens result in 401 Unauthorized errors.
  • Applications must handle token expiration gracefully.
  • Refresh tokens allow obtaining new access tokens without re-authentication.

Memory trick: Expired Tokens Cause Unauthorized Trouble.

More Understanding and Using APIs questions