---
category: [Administration & Integrations, Platform and Product Extensions, Platform and Product Extensions/Integration, Administration & Integrations/Custom Integrations & Apps, Platform and Product Extensions/Workday Extend]
keyword: Extend
nav: wcp_docs
parent_url: /wcp_docs/
title: Get a Refresh Token for WCPISU Authentication
layout: subsection
---

### Prerequisites

<a id="prereq_N10021_N1001E_N10001"></a>
-   An Integration System User (ISU) user.
-   API client ID and secret of your custom app. You can get these values by selecting <b>API Clients</b> from the <b>Console</b> section of the Developer Site menu.
-   An HTTP REST API client tester, such as Postman.
-   A Base64 encoding scheme.


### Context

<a id="context_N10049_N1001E_N10001"></a>
<b>Note:</b> The `WCPISU` authentication type is a legacy mechanism for authenticating apps with an ISU user. Instead of using `WCPISU`, Workday recommends the simplified `ISU` authentication type, which is an improved and simpler version. Existing apps with Presentation Components can continue using `WCPISU`, but new apps must use `ISU`. Workday strongly recommends that existing apps migrate to `ISU`. To migrate an existing app to `ISU`:

1.  Add the `ISU` authentication scheme to `authTypes` in the SMD.
2.  Update the PMD endpoint definitions that use `WCPISU`. Replace the `authType` value with the `id` of the ISU scheme declared in the SMD.


See [Steps: Set Up ISU Authentication for Apps](/wcp_docs/GUID-3277fec3-24c9-41da-9840-c61b41033f28-enHYPHENus.html).

To use the WCPISU authentication scheme in your custom app, you need to get refresh tokens for the ISU and save them in the credential store. Presentation Components retrieve the refresh token from the credential store and use it to authenticate a client request.

<b>Note:</b> Your account region determines the base URL of the authorization endpoints. See [Reference: Workday Extend API Gateways and Authorization Base URLs](/wcp_docs/dlh1653340161856.html). Use the appropriate base URL in these authorization endpoints:

```
https://{regionAuthBaseUrl}/v1/authorize
https://{regionAuthBaseUrl}/v1/token
```

### Steps

1.  <a id="step_N10053_N10050_N1001E_N10001"></a>Sign in your tenant as the ISU user.

    <b>Note:</b> Selecting the <b>Do Not Allow UI Sessions</b> option on the <b>Edit Workday Accounts</b> task prevents the ISU user from signing in to the Workday UI. You can clear the option before you store tokens in the CredStore, and select the option again afterwards.

2.  <a id="step_N1005C_N10050_N1001E_N10001"></a>On a browser, enter this URL: `https://{regionAuthBaseUrl}/v1/authorize?response_type=code&client_id={clientId}&redirect_uri={redirectUri}`.

<table><thead><tr><th>    Option</th><th>    Description</th></tr></thead><tbody><tr><td><b>response_type</b></td><td>Set this value to <code>code</code> for the Authorization Code grant type.</td></tr><tr><td><b>client_id</b></td><td>The Client ID of your custom app.</td></tr><tr><td><b>redirectUri</b></td><td>The Redirect URI of your custom app.</td></tr></tbody></table><br/>

3.  <a id="step_N100A5_N10050_N1001E_N10001"></a>When prompted, enter your tenant alias.
4.  <a id="step_N100E2_N10050_N1001E_N10001"></a>After you sign in, the browser URL displays your redirect URI with a code. Save the code value on your clipboard. You'll use this code when you invoke the `/token` endpoint in the next step.

    Example:

    ```
    http://localhost:8123/?code=59a0c0a2-8b9a-47e6-a509-0a79f4e4c46a
    ```

    The access `code` returned by the `/authorize` endpoint expires in 10 minutes.

5.  <a id="step_N100F8_N10050_N1001E_N10001"></a>On an HTTP REST API client testing tool such as Postman or SOAP UI, submit this HTTP request:

    `https://{regionAuthBaseUrl}/v1/token`

<table><thead></thead><tbody><tr><td>HTTP Method</td><td>POST</td></tr><tr><td>HTTP Endpoint</td><td>https://{regionAuthBaseUrl}/v1/token</td></tr><tr><td>Headers</td><td><p><b>Content-Type</b>: <code>application/x-www-form-urlencoded</code></p> <p><b>Authorization</b>: <code>Basic {base64-encoded-clientIdAndSecret}</code></p> <p>Where <code>{base64-encoded-clientIdAndSecret}</code> is the base64 encoded value of <code>{clientId}:{clientSecret}</code>.</p> <p>To get the <code>{base64-encoded-clientIdAndSecret}</code> value:</p> <ul><li>    Get the Client ID and Client Secret from the Console.
</li><li>    Concatenate the client ID and secret using a colon (:). Example: Y2YyYmY2MWYtNDU4N:ad3mrxa0lhxai3xo7d2uz9ar
</li><li>    Encode the concatenated value in Base64.
</li></ul></td></tr><tr><td>Body parameters</td><td><p><b>grant_type</b>: Set this value to <code>authorization_code</code>.</p> <p><b>code</b>: Enter the <b>Authorization</b> code that you saved from the <code>/authorize</code> endpoint in the previous step.</p> Note: If you're using Postman, make sure that you select <code>x-www-form-urlencoded</code> when you enter the <b>Body</b> parameters.</td></tr></tbody></table><br/>

6.  <a id="step_N10189_N10050_N1001E_N10001"></a>After you submit the request, the `/token` endpoint returns the `refresh_token` in the response data. Copy the `refresh_token` value to your clipboard. You'll use this refresh token on the Refresh Tokens grid on <b>Create External Client CredStore</b> task.

    The `refresh_token` returned by the `/token` endpoint doesn't expire.



### Next Steps

<a id="postreq_N101A8_N1001E_N10001"></a>
[Create External Client CredStore](/wcp_docs/gqs1527493104452.html#).

