b2c_tooling_sdk.slas
SLAS Shopper Login token retrieval.
Mirrors the TypeScript @salesforce/b2c-tooling-sdk/slas subpath export. Provides functions to obtain shopper access tokens from the SLAS Shopper Login service, supporting public (PKCE) and private (client_credentials / HTTP Basic) client flows for both guest and registered customers.
This subpackage is intentionally NOT re-exported from the top-level b2c_tooling_sdk package; import it directly:
from b2c_tooling_sdk.slas import get_guest_tokenClasses
SlasTokenConfig
class SlasTokenConfigConfiguration for SLAS shopper token retrieval.
Attributes
| Name | Type | Description |
|---|---|---|
short_code | str | SCAPI short code. |
organization_id | str | Organization ID in f_ecom_xxxx_yyy format. |
slas_client_id | str | SLAS client ID. |
site_id | str | B2C Commerce site/channel ID. |
redirect_uri | str | OAuth redirect URI. |
slas_client_secret | str | None | SLAS client secret (None = public client). |
SlasTokenResponse
class SlasTokenResponseResponse from SLAS token endpoints.
Attributes
| Name | Type | Description |
|---|---|---|
access_token | str | The shopper access token (JWT). |
refresh_token | str | The refresh token for silent renewal. |
expires_in | int | Access-token lifetime in seconds. |
token_type | str | The token type (typically Bearer). |
usid | str | The unique shopper identifier. |
customer_id | str | The customer identifier. |
id_token | str | None | Optional OpenID Connect ID token. |
from_dict method
def from_dict(data: dict[str, Any]) -> SlasTokenResponseBuild a SlasTokenResponse from a raw SLAS JSON body.
SlasRegisteredLoginConfig
class SlasRegisteredLoginConfig(SlasTokenConfig)Configuration for registered customer login.
Attributes
| Name | Type | Description |
|---|---|---|
shopper_login | str | Shopper login/username. |
shopper_password | str | Shopper password. |
Functions
generate_code_challenge
def generate_code_challenge(verifier: str) -> strGenerate a PKCE code challenge from a code verifier using S256.
Parameters
| Name | Type | Description |
|---|---|---|
verifier | str | The code verifier to hash. |
Returns: The base64url-encoded (unpadded) SHA-256 hash of the verifier.
generate_code_verifier
def generate_code_verifier(random_bytes: bytes | None = None) -> strGenerate a cryptographically random PKCE code verifier.
Parameters
| Name | Type | Description |
|---|---|---|
random_bytes | bytes | None | Optional raw random bytes to encode (for deterministic tests). When omitted, secrets.token_bytes supplies CODE_VERIFIER_BYTES bytes. |
Returns: A 128-character base64url-encoded random string.
get_guest_token
async def get_guest_token(config: SlasTokenConfig) -> SlasTokenResponseRetrieve a guest shopper access token from SLAS.
- Private client (
slas_client_secretset): uses theclient_credentialsgrant. - Public client (no secret): uses the PKCE authorization-code flow with
hint=guest.
Parameters
| Name | Type | Description |
|---|---|---|
config | SlasTokenConfig | SLAS token configuration. |
Returns: The token response including access_token and refresh_token.
get_registered_token
async def get_registered_token(config: SlasRegisteredLoginConfig) -> SlasTokenResponseRetrieve a registered-customer access token from SLAS.
Uses the /oauth2/login endpoint with shopper credentials, then exchanges the returned authorization code for an access token.
The registered-customer flow is PKCE-protected for both public and private clients: a code_challenge is always presented at the /oauth2/login step, so the matching code_verifier must always be sent at the token exchange with the authorization_code_pkce grant.
- Public client: PKCE token exchange (no client secret).
- Private client: PKCE token exchange, plus HTTP Basic authentication using the client secret. The client must NOT drop PKCE, or SLAS rejects the exchange with
400 code_verifier is required.
Parameters
| Name | Type | Description |
|---|---|---|
config | SlasRegisteredLoginConfig | SLAS token configuration including shopper credentials. |
Returns: The token response including access_token and refresh_token.