---
editLink: false
lastUpdated: false
outline: [2, 3]
---

<!-- Generated by python/b2c-tooling-sdk/scripts/generate_api_docs.py. Do not edit. -->

# b2c_tooling_sdk.slas

SLAS Shopper Login token retrieval.

Mirrors the TypeScript `@salesforce/b2c-tooling-sdk/slas` subpath export.
Provides functions to obtain shopper access tokens from the SLAS Shopper Login
service, supporting public (PKCE) and private (`client_credentials` / HTTP
Basic) client flows for both guest and registered customers.

This subpackage is intentionally NOT re-exported from the top-level
`b2c_tooling_sdk` package; import it directly:

```python
from b2c_tooling_sdk.slas import get_guest_token
```

## Classes

### SlasTokenConfig {#slastokenconfig}

```python
class SlasTokenConfig
```

Configuration for SLAS shopper token retrieval.

**Attributes**

| Name | Type | Description |
| --- | --- | --- |
| `short_code` | `str` | SCAPI short code. |
| `organization_id` | `str` | Organization ID in `f_ecom_xxxx_yyy` format. |
| `slas_client_id` | `str` | SLAS client ID. |
| `site_id` | `str` | B2C Commerce site/channel ID. |
| `redirect_uri` | `str` | OAuth redirect URI. |
| `slas_client_secret` | `str \| None` | SLAS client secret (`None` = public client). |

### SlasTokenResponse {#slastokenresponse}

```python
class SlasTokenResponse
```

Response from SLAS token endpoints.

**Attributes**

| Name | Type | Description |
| --- | --- | --- |
| `access_token` | `str` | The shopper access token (JWT). |
| `refresh_token` | `str` | The refresh token for silent renewal. |
| `expires_in` | `int` | Access-token lifetime in seconds. |
| `token_type` | `str` | The token type (typically `Bearer`). |
| `usid` | `str` | The unique shopper identifier. |
| `customer_id` | `str` | The customer identifier. |
| `id_token` | `str \| None` | Optional OpenID Connect ID token. |

#### from_dict <Badge type="info" text="method" /> {#slastokenresponse-from-dict}

```python
def from_dict(data: dict[str, Any]) -> SlasTokenResponse
```

Build a [`SlasTokenResponse`](/python/api/slas#slastokenresponse) from a raw SLAS JSON body.

### SlasRegisteredLoginConfig {#slasregisteredloginconfig}

```python
class SlasRegisteredLoginConfig(SlasTokenConfig)
```

Configuration for registered customer login.

**Attributes**

| Name | Type | Description |
| --- | --- | --- |
| `shopper_login` | `str` | Shopper login/username. |
| `shopper_password` | `str` | Shopper password. |

## Functions

### generate_code_challenge {#generate-code-challenge}

```python
def generate_code_challenge(verifier: str) -> str
```

Generate a PKCE code challenge from a code verifier using S256.

**Parameters**

| Name | Type | Description |
| --- | --- | --- |
| `verifier` | `str` | The code verifier to hash. |

**Returns:** The base64url-encoded (unpadded) SHA-256 hash of the verifier.

### generate_code_verifier {#generate-code-verifier}

```python
def generate_code_verifier(random_bytes: bytes | None = None) -> str
```

Generate a cryptographically random PKCE code verifier.

**Parameters**

| Name | Type | Description |
| --- | --- | --- |
| `random_bytes` | `bytes \| None` | Optional raw random bytes to encode (for deterministic tests). When omitted, `secrets.token_bytes` supplies `CODE_VERIFIER_BYTES` bytes. |

**Returns:** A 128-character base64url-encoded random string.

### get_guest_token {#get-guest-token}

```python
async def get_guest_token(config: SlasTokenConfig) -> SlasTokenResponse
```

Retrieve a guest shopper access token from SLAS.

- **Private client** (`slas_client_secret` set): uses the
  `client_credentials` grant.
- **Public client** (no secret): uses the PKCE authorization-code flow with
  `hint=guest`.

**Parameters**

| Name | Type | Description |
| --- | --- | --- |
| `config` | `SlasTokenConfig` | SLAS token configuration. |

**Returns:** The token response including `access_token` and `refresh_token`.

### get_registered_token {#get-registered-token}

```python
async def get_registered_token(config: SlasRegisteredLoginConfig) -> SlasTokenResponse
```

Retrieve a registered-customer access token from SLAS.

Uses the `/oauth2/login` endpoint with shopper credentials, then exchanges
the returned authorization code for an access token.

The registered-customer flow is PKCE-protected for **both** public and
private clients: a `code_challenge` is always presented at the
`/oauth2/login` step, so the matching `code_verifier` must always be sent
at the token exchange with the `authorization_code_pkce` grant.

- **Public client**: PKCE token exchange (no client secret).
- **Private client**: PKCE token exchange, plus HTTP Basic authentication
  using the client secret. The client must NOT drop PKCE, or SLAS rejects the
  exchange with `400 code_verifier is required`.

**Parameters**

| Name | Type | Description |
| --- | --- | --- |
| `config` | `SlasRegisteredLoginConfig` | SLAS token configuration including shopper credentials. |

**Returns:** The token response including `access_token` and `refresh_token`.
