import { BaseClient, ClientConfig, Response } from "@commerce-apps/core"; import type { CommonParameters } from "@commerce-apps/core"; import type { OperationOptions } from "retry"; import type { RequestInit } from "node-fetch"; import type { CompositeParameters, CustomRequestBody, QueryParameters, RequireParametersUnlessAllAreOptional } from "../../types"; import type { AuthenticateFinishRequest, AuthenticateResult, GrantType, PasskeyUser, PublicKeyCredentialRequestOptions, RegistrationFinishRequest, ResponseType, TokenActionRequest, TokenResponse } from '../models/index'; export type AuthorizeCustomerResponseTypeEnum = 'code'; export type AuthorizeCustomerScopeEnum = 'openid' | 'offline_access' | 'email'; export type AuthorizePasswordlessCustomerModeEnum = 'callback' | 'sms' | 'email'; export type AuthorizeWebauthnRegistrationModeEnum = 'callback' | 'sms' | 'email'; export type GetPasswordLessAccessTokenGrantTypeEnum = 'authorization_code' | 'refresh_token' | 'client_credentials' | 'authorization_code_pkce' | 'session_bridge'; export type GetPasswordResetTokenModeEnum = 'callback' | 'sms' | 'email'; export type GetSessionBridgeAccessTokenGrantTypeEnum = 'authorization_code' | 'refresh_token' | 'client_credentials' | 'authorization_code_pkce' | 'session_bridge'; export type GetTrustedAgentAccessTokenGrantTypeEnum = 'authorization_code' | 'refresh_token' | 'client_credentials' | 'authorization_code_pkce' | 'session_bridge'; export type GetTrustedAgentAuthorizationTokenResponseTypeEnum = 'code'; export type GetTrustedSystemAccessTokenGrantTypeEnum = 'authorization_code' | 'refresh_token' | 'client_credentials' | 'authorization_code_pkce' | 'session_bridge'; export type GetTrustedSystemAccessTokenHintEnum = 'ts_ext_on_behalf_of'; export type GetTrustedSystemAccessTokenIdpOriginEnum = 'apple' | 'auth0' | 'azure' | 'azure_adb2c' | 'cognito' | 'default' | 'ecom' | 'facebook' | 'forgerock' | 'gigya' | 'gigya_socialize' | 'google' | 'okta' | 'ping' | 'salesforce'; export type IntrospectTokenTokenTypeHintEnum = 'access_token' | 'refresh_token'; export type LogoutCustomerHintEnum = 'all-sessions'; export type RequestOtpModeEnum = 'callback' | 'sms' | 'email'; export type RevokeTokenTokenTypeHintEnum = 'access_token' | 'refresh_token'; export type authenticateCustomerBodyType = { client_id?: string; response_type?: ResponseType; redirect_uri: string; state?: string; scope?: string; usid?: string; channel_id: string; code_challenge?: string; }; export type authorizePasswordlessCustomerBodyType = { user_id: string; mode: string; locale?: string; usid?: string; channel_id: string; callback_uri?: string; last_name?: string; email?: string; first_name?: string; phone_number?: string; customer_no?: string; }; export type authorizeWebauthnRegistrationBodyType = { user_id: string; mode: string; channel_id: string; locale?: string; client_id?: string; code_challenge?: string; callback_uri?: string; idp_name?: string; hint?: string; }; export type getAccessTokenBodyType = { refresh_token?: string; code?: string; usid?: string; grant_type: GrantType; redirect_uri?: string; code_verifier?: string; client_id?: string; channel_id?: string; dnt?: string; }; export type getPasswordLessAccessTokenBodyType = { grant_type: string; hint: string; pwdless_login_token: string; client_id?: string; code_verifier?: string; login_id?: string; }; export type getPasswordResetTokenBodyType = { user_id: string; mode: string; channel_id: string; locale?: string; client_id?: string; code_challenge?: string; callback_uri?: string; idp_name?: string; hint?: string; }; export type getSessionBridgeAccessTokenBodyType = { code: string; client_id: string; channel_id: string; code_verifier: string; dwsid: string; grant_type: string; login_id: string; dwsgst?: string; dwsrst?: string; usid?: string; dnt?: string; }; export type getTrustedAgentAccessTokenBodyType = { agent_id?: string; client_id: string; channel_id: string; code_verifier: string; grant_type: string; login_id: string; idp_origin: string; usid?: string; dnt?: string; state?: string; }; export type getTrustedSystemAccessTokenBodyType = { usid?: string; grant_type: string; hint: string; login_id: string; idp_origin: string; client_id: string; channel_id: string; email_id?: string; dnt?: string; }; export type introspectTokenBodyType = { token: string; token_type_hint?: string; }; export type requestOtpBodyType = { client_id: string; channel_id: string; user_id: string; mode: string; email?: string; callback_uri?: string; locale?: string; }; export type resetPasswordBodyType = { client_id: string; pwd_action_token: string; code_verifier?: string; new_password?: string; channel_id: string; hint?: string; user_id?: string; }; export type revokeTokenBodyType = { token: string; token_type_hint?: string; }; export type startWebauthnAuthenticationBodyType = { tenant_id?: string; client_id: string; channel_id: string; user_id?: string; }; export type startWebauthnUserRegistrationBodyType = { client_id?: string; pwd_action_token: string; user_id: string; channel_id: string; display_name?: string; nick_name?: string; }; export type verifyOtpBodyType = { pwd_action_token: string; client_id: string; channel_id: string; user_id: string; }; /** * [Auth](https://developer.salesforce.com/docs/commerce/commerce-api/references?meta=auth:Summary) * ================================== * * *[Download API specification](https://developer.salesforce.com/static/commercecloud/commerce-api/auth/auth-oas-v1-public.yaml) # API Overview The Shopper Login and API Access Service (SLAS) enables secure access to Commerce Cloud’s Shopper APIs for a wide range of headless commerce applications. **Important:** Before using this API, see [Authorization for Shopper APIs](https://developer.salesforce.com/docs/commerce/commerce-api/guide/authorization-for-shopper-apis.html) in the Get Started guides and the more detailed [SLAS guides](https://developer.salesforce.com/docs/commerce/commerce-api/guide/slas.html) for instructions on setting up a SLAS client, obtaining credentials, as well as flow and use case information. For load shedding and rate limiting information, see [Load Shedding and Rate Limiting.](https://developer.salesforce.com/docs/commerce/commerce-api/guide/throttle-rates.html)*
* * For instructions on how to retrieve access token for admin APIs: https://developer.salesforce.com/docs/commerce/commerce-api/guide/authorization-for-admin-apis.html

* Example with admin auth * * ```typescript * import { ShopperLogin, ClientConfig } from "commerce-sdk"; * // or * const { ShopperLogin, ClientConfig } = require("commerce-sdk"); * * const clientConfig: ClientConfig = { * parameters: { * clientId: "XXXXXX", * organizationId: "XXXX", * shortCode: "XXX", * siteId: "XX" * } * }; * * token = { access_token: 'INSERT_ACCESS_TOKEN_HERE' }; * * clientConfig.headers['authorization'] = `Bearer ${token.access_token}`; * const authClient = new ShopperLogin(clientConfig); * ``` * * * API Version: 1.4.4
* Last Updated:
*
* */ export declare class ShopperLogin extends BaseClient { constructor(config: ClientConfig); /** * This follows the authorization code grant flow as defined by the OAuth 2.1 standard. It also uses a proof key for code exchange (PKCE). For PKCE values: - The `code_verifier` string is a random string used for the `/token` endpoint request. - The `code_challenge` is an encoded version of the `code_verifier` string using an SHA-256 hash. The request must include a basic authorization header that contains a Base64 encoded version of the following string: `:`. Required parameters: `code_challenge`, `channel_id`, `client_id`, and `redirect_uri`. Optional parameters: `usid`. The SLAS `/login` endpoint redirects back to the redirect URI and returns an authorization code. Calls to `/login` made with the same loginId and tenantId within 1 second result in a conflict. * * If you would like to get a raw Response object use the other authenticateCustomer function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.client_id - SLAS client ID. Required when the grant type is `authorization_code_pkce`. * @param options.body.response_type - Must be `code`. Indicates that the client wants an authorization code (when the grant type is `authorization_code`). * @param options.body.redirect_uri - The URI to which the server redirects the browser after the user grants the authorization. The URI must be registered with the SLAS client. A variety of URI formats and wildcards for host are supported, but app links like airbnb:// or fb:// are not. Examples of supported URIs: Examples of supported URIs: - `http://localhost:3000/callback` - `https://example.com/callback` - `com.example.app:redirect_uri_path` - ` *.subdomain.topleveldomain.com` * @param options.body.state - Value to be sent by the client to determine the state between the authorization request and the server response. Optional, but strongly recommended. * @param options.body.scope - Scopes to limit an application\'s access to a user\'s account. * @param options.body.usid - The unique shopper ID. * @param options.body.channel_id - The channel that the request is for. For a B2C Commerce request, this is angalous to the site ID. * @param options.body.code_challenge - PKCE code verifier. Created by the client calling the `login` endpoint. The `code_challenge` is created by SHA256 hashing the `code_verifier` and Base64 encoding the resulting hash. The `code_verifier` should be a high entropy cryptographically random string with a minimum of 43 characters and a maximum of 128 characters. The `code_challenge` is optional when using a private client id for the token request. * * @returns A promise of type void. */ authenticateCustomer(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: authenticateCustomerBodyType; }>): Promise; /** * This follows the authorization code grant flow as defined by the OAuth 2.1 standard. It also uses a proof key for code exchange (PKCE). For PKCE values: - The `code_verifier` string is a random string used for the `/token` endpoint request. - The `code_challenge` is an encoded version of the `code_verifier` string using an SHA-256 hash. The request must include a basic authorization header that contains a Base64 encoded version of the following string: `:`. Required parameters: `code_challenge`, `channel_id`, `client_id`, and `redirect_uri`. Optional parameters: `usid`. The SLAS `/login` endpoint redirects back to the redirect URI and returns an authorization code. Calls to `/login` made with the same loginId and tenantId within 1 second result in a conflict. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.client_id - SLAS client ID. Required when the grant type is `authorization_code_pkce`. * @param options.body.response_type - Must be `code`. Indicates that the client wants an authorization code (when the grant type is `authorization_code`). * @param options.body.redirect_uri - The URI to which the server redirects the browser after the user grants the authorization. The URI must be registered with the SLAS client. A variety of URI formats and wildcards for host are supported, but app links like airbnb:// or fb:// are not. Examples of supported URIs: Examples of supported URIs: - `http://localhost:3000/callback` - `https://example.com/callback` - `com.example.app:redirect_uri_path` - ` *.subdomain.topleveldomain.com` * @param options.body.state - Value to be sent by the client to determine the state between the authorization request and the server response. Optional, but strongly recommended. * @param options.body.scope - Scopes to limit an application\'s access to a user\'s account. * @param options.body.usid - The unique shopper ID. * @param options.body.channel_id - The channel that the request is for. For a B2C Commerce request, this is angalous to the site ID. * @param options.body.code_challenge - PKCE code verifier. Created by the client calling the `login` endpoint. The `code_challenge` is created by SHA256 hashing the `code_verifier` and Base64 encoding the resulting hash. The `code_verifier` should be a high entropy cryptographically random string with a minimum of 43 characters and a maximum of 128 characters. The `code_challenge` is optional when using a private client id for the token request. * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type void otherwise. */ authenticateCustomer(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: authenticateCustomerBodyType; }>, rawResponse?: T): Promise; /** * This is the first step of the OAuth 2.1 authorization code flow, in which a user can log in via federation to the IDP configured for the client. After successfully logging in, the user gets an authorization code via a redirect URI. You can call this endpoint from the front channel (the browser). * * If you would like to get a raw Response object use the other authorizeCustomer function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.parameters.redirect_uri - The redirect for Account Manager to redirect to. A variety of URI formats and wildcard for host are supported, but app links like `airbnb://` or `fb://` are not. Examples of supported URIs: - `http://localhost:3000/callback` - `https://example.com/callback` - `com.example.app:redirect_uri_path` - ` *.subdomain.topleveldomain.com` * @param options.parameters.response_type - Must be `code`. Indicates that the caller wants an authorization code. * @param options.parameters.client_id - The SLAS public client ID or SLAS private client ID for use with trusted-agent requests. When using a private client ID a PKCE code challenge is not required. * @param options.parameters.scope - * @param options.parameters.state - Value to send the client to determine the state between the authorization request and the server response. Optional, but strongly recommended. * @param options.parameters.usid - A unique shopper identifier (USID). If not provided, a new USID is generated. * @param options.parameters.hint - Name of an identity provider (IDP) to optionally redirect to, thereby skipping the IDP selection step. To use a public client, set `hint` to `guest` and use a public client ID to get an authorization code. If no `hint` is provided, the preferred IDP of the tenant is used by default. For session bridge authorization the `hint` should be set to `sb-user` for a registered customer and to `sb-guest` for a guest. For session bridge authorization the SLAS Client `sfcc.session_bridge` scope. * @param options.parameters.channel_id - The channel that this request is for. For a B2C Commerce request, this is angalous to the site ID. * @param options.parameters.code_challenge - PKCE code challenge. Created by the caller. The `code_challenge` is created by SHA256 hashing the `code_verifier` and Base64 encoding the resulting hash. The `code_verifier` should be a high entropy cryptographically random string with a minimum of 43 characters and a maximum of 128 characters. The *`code_challenge` and 'code_verifier'* are required if a using SLAS public `client_id`. * @param options.parameters.ui_locales - End-User's preferred languages and scripts for the user interface, represented as a space-separated list of BCP47 [RFC5646] language tag values, ordered by preference. For example, the value `fr-CA fr en` represents a preference for French as spoken in Canada, then French (without a region designation), followed by English (without a region designation). In most cases the IDP supports one language tag and has a default language set on the server. SLAS will support the space-separated list and pass them to the IDP. * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * * @returns A promise of type void. */ authorizeCustomer(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; redirect_uri: string; response_type: AuthorizeCustomerResponseTypeEnum; client_id: string; scope?: AuthorizeCustomerScopeEnum; state?: string; usid?: string; hint?: string; channel_id?: string; code_challenge?: string; ui_locales?: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; }>): Promise; /** * This is the first step of the OAuth 2.1 authorization code flow, in which a user can log in via federation to the IDP configured for the client. After successfully logging in, the user gets an authorization code via a redirect URI. You can call this endpoint from the front channel (the browser). * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.parameters.redirect_uri - The redirect for Account Manager to redirect to. A variety of URI formats and wildcard for host are supported, but app links like `airbnb://` or `fb://` are not. Examples of supported URIs: - `http://localhost:3000/callback` - `https://example.com/callback` - `com.example.app:redirect_uri_path` - ` *.subdomain.topleveldomain.com` * @param options.parameters.response_type - Must be `code`. Indicates that the caller wants an authorization code. * @param options.parameters.client_id - The SLAS public client ID or SLAS private client ID for use with trusted-agent requests. When using a private client ID a PKCE code challenge is not required. * @param options.parameters.scope - * @param options.parameters.state - Value to send the client to determine the state between the authorization request and the server response. Optional, but strongly recommended. * @param options.parameters.usid - A unique shopper identifier (USID). If not provided, a new USID is generated. * @param options.parameters.hint - Name of an identity provider (IDP) to optionally redirect to, thereby skipping the IDP selection step. To use a public client, set `hint` to `guest` and use a public client ID to get an authorization code. If no `hint` is provided, the preferred IDP of the tenant is used by default. For session bridge authorization the `hint` should be set to `sb-user` for a registered customer and to `sb-guest` for a guest. For session bridge authorization the SLAS Client `sfcc.session_bridge` scope. * @param options.parameters.channel_id - The channel that this request is for. For a B2C Commerce request, this is angalous to the site ID. * @param options.parameters.code_challenge - PKCE code challenge. Created by the caller. The `code_challenge` is created by SHA256 hashing the `code_verifier` and Base64 encoding the resulting hash. The `code_verifier` should be a high entropy cryptographically random string with a minimum of 43 characters and a maximum of 128 characters. The *`code_challenge` and 'code_verifier'* are required if a using SLAS public `client_id`. * @param options.parameters.ui_locales - End-User's preferred languages and scripts for the user interface, represented as a space-separated list of BCP47 [RFC5646] language tag values, ordered by preference. For example, the value `fr-CA fr en` represents a preference for French as spoken in Canada, then French (without a region designation), followed by English (without a region designation). In most cases the IDP supports one language tag and has a default language set on the server. SLAS will support the space-separated list and pass them to the IDP. * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type void otherwise. */ authorizeCustomer(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; redirect_uri: string; response_type: AuthorizeCustomerResponseTypeEnum; client_id: string; scope?: AuthorizeCustomerScopeEnum; state?: string; usid?: string; hint?: string; channel_id?: string; code_challenge?: string; ui_locales?: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; }>, rawResponse?: T): Promise; /** * This endpoint allows customers to authenticate when their configured identity provider is inaccessible. It provides an alternative authentication path through passwordless login methods like email or SMS verification. * * If you would like to get a raw Response object use the other authorizePasswordlessCustomer function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.parameters.register_customer - When set to `true`, creates a new customer profile in B2C Commerce if one doesn't already exist. Requires `last_name` and `email` body parameters unless `user_id` is an email address. Optionally accepts `first_name` and `phone_number` body parameters. If the customer profile doesn't exist, it is created when the TOTP is validated via the `passwordless/token` endpoint. When set to `false` (or omitted), no customer profile is created in B2C Commerce. * @param options.parameters.strict_verify - When set to `true`, blocks the passwordless login request and returns a `400` error if the shopper's email is not verified. Use this to enforce shopper email verification before allowing passwordless authentication. Available in B2C Commerce version 26.6 and later. Default: `false` * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.user_id - User ID for logging in. * @param options.body.mode - Password Action delivery modes * @param options.body.locale - The locale of the template. Required when the mode is `email` or `sms`. * @param options.body.usid - The shopper\'s unique identifier, if known. If not provided, a new USID is generated. * @param options.body.channel_id - The channel (B2C Commerce site) that the user is associated with. * @param options.body.callback_uri - The callback URI. Required when the mode is `callback`. The `callback_uri` property will be validated against the callback URIs that have been registered with the SLAS client. The callback URI _must_ be a `POST` endpoint because the token will be included in the body. Wildcards are not allowed in the callback_uri because this is a security risk that can expose the token. This is not considered an OAuth2 callback_url. * @param options.body.last_name - The user\'s last name. Required when `register_customer` is `true`. The `last_name` parameter is not used when `register_customer` parameter is not added or is `false`. * @param options.body.email - The user\'s email address. Required when `register_customer` is `true` and `user_id` is not an email address. The `email` parameter is not used when `register_customer` parameter is not added or is `false`. * @param options.body.first_name - The user\'s first name. Optional when `register_customer` is `true`. The `first_name` parameter is not used when `register_customer` parameter is not added or is `false`. * @param options.body.phone_number - The user\'s phone number. Optional when `register_customer` is `true`. The `phone_number` parameter is not used when `register_customer` parameter is not added or is `false`. * @param options.body.customer_no - The customer number assigned to the shopper profile when `register_customer` is set to `true`. If the `customer_no` already exists, the request fails. The `customer_no` parameter is optional and only used when `register_customer` is set to `true`. * * @returns A promise of type string. */ authorizePasswordlessCustomer(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; register_customer?: string; strict_verify?: boolean; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: authorizePasswordlessCustomerBodyType; }>): Promise; /** * This endpoint allows customers to authenticate when their configured identity provider is inaccessible. It provides an alternative authentication path through passwordless login methods like email or SMS verification. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.parameters.register_customer - When set to `true`, creates a new customer profile in B2C Commerce if one doesn't already exist. Requires `last_name` and `email` body parameters unless `user_id` is an email address. Optionally accepts `first_name` and `phone_number` body parameters. If the customer profile doesn't exist, it is created when the TOTP is validated via the `passwordless/token` endpoint. When set to `false` (or omitted), no customer profile is created in B2C Commerce. * @param options.parameters.strict_verify - When set to `true`, blocks the passwordless login request and returns a `400` error if the shopper's email is not verified. Use this to enforce shopper email verification before allowing passwordless authentication. Available in B2C Commerce version 26.6 and later. Default: `false` * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.user_id - User ID for logging in. * @param options.body.mode - Password Action delivery modes * @param options.body.locale - The locale of the template. Required when the mode is `email` or `sms`. * @param options.body.usid - The shopper\'s unique identifier, if known. If not provided, a new USID is generated. * @param options.body.channel_id - The channel (B2C Commerce site) that the user is associated with. * @param options.body.callback_uri - The callback URI. Required when the mode is `callback`. The `callback_uri` property will be validated against the callback URIs that have been registered with the SLAS client. The callback URI _must_ be a `POST` endpoint because the token will be included in the body. Wildcards are not allowed in the callback_uri because this is a security risk that can expose the token. This is not considered an OAuth2 callback_url. * @param options.body.last_name - The user\'s last name. Required when `register_customer` is `true`. The `last_name` parameter is not used when `register_customer` parameter is not added or is `false`. * @param options.body.email - The user\'s email address. Required when `register_customer` is `true` and `user_id` is not an email address. The `email` parameter is not used when `register_customer` parameter is not added or is `false`. * @param options.body.first_name - The user\'s first name. Optional when `register_customer` is `true`. The `first_name` parameter is not used when `register_customer` parameter is not added or is `false`. * @param options.body.phone_number - The user\'s phone number. Optional when `register_customer` is `true`. The `phone_number` parameter is not used when `register_customer` parameter is not added or is `false`. * @param options.body.customer_no - The customer number assigned to the shopper profile when `register_customer` is set to `true`. If the `customer_no` already exists, the request fails. The `customer_no` parameter is optional and only used when `register_customer` is set to `true`. * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type string otherwise. */ authorizePasswordlessCustomer(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; register_customer?: string; strict_verify?: boolean; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: authorizePasswordlessCustomerBodyType; }>, rawResponse?: T): Promise; /** * Authorizes a user to register a WebAuthn credential (passkey). This endpoint validates the user's credentials and creates a password action token that can be used to start the registration process. The token is sent to the user via the specified channel (email or SMS). The SLAS client must have the `sfcc.pwdless_login` scope to access this endpoint. * * If you would like to get a raw Response object use the other authorizeWebauthnRegistration function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.user_id - User ID for logging in. This is the id that is used to log into SFCC. * @param options.body.mode - Password Action delivery modes * @param options.body.channel_id - The channel (B2C Commerce site) that the user is associated with. * @param options.body.locale - The locale of the template. Required when the mode is `email` or `sms`. * @param options.body.client_id - -| The public client ID. Requires setting `grant_type` to `passwordless_login_pkce`. When using the `hint` query parameter either a public or private client ID can be used. * @param options.body.code_challenge - PKCE code challenge. Created by the client. The `code_challenge` is created by SHA256 hashing the `code_verifier` and Base64 encoding the resulting hash. The `code_verifier` should be a high entropy cryptographically random string with a minimum of 43 characters and a maximum of 128 characters. Requires setting `grant_type` to `passwordless_login_pkce` * @param options.body.callback_uri - The callback uri. Required when the mode is `callback`. The `callback_uri` property will be validated against the callback URIs that have been registered with the SLAS client. The callback URI _must_ be a `POST` endpoint because the token will be included in the body. Wildcards are not allowed in the callback_uri because this is a security risk that can expose the token. This is not considered an OAuth2 callback_url. * @param options.body.idp_name - The name of the 3rd party identity provider for the user ID * @param options.body.hint - Adding a `hint` query parameter with a value of `cross_device` will remove the need to have the code_challenge for password reset request. If the `hint` query parameter is used it must also be used in the password reset request. * * @returns A promise of type void. */ authorizeWebauthnRegistration(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: authorizeWebauthnRegistrationBodyType; }>): Promise; /** * Authorizes a user to register a WebAuthn credential (passkey). This endpoint validates the user's credentials and creates a password action token that can be used to start the registration process. The token is sent to the user via the specified channel (email or SMS). The SLAS client must have the `sfcc.pwdless_login` scope to access this endpoint. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.user_id - User ID for logging in. This is the id that is used to log into SFCC. * @param options.body.mode - Password Action delivery modes * @param options.body.channel_id - The channel (B2C Commerce site) that the user is associated with. * @param options.body.locale - The locale of the template. Required when the mode is `email` or `sms`. * @param options.body.client_id - -| The public client ID. Requires setting `grant_type` to `passwordless_login_pkce`. When using the `hint` query parameter either a public or private client ID can be used. * @param options.body.code_challenge - PKCE code challenge. Created by the client. The `code_challenge` is created by SHA256 hashing the `code_verifier` and Base64 encoding the resulting hash. The `code_verifier` should be a high entropy cryptographically random string with a minimum of 43 characters and a maximum of 128 characters. Requires setting `grant_type` to `passwordless_login_pkce` * @param options.body.callback_uri - The callback uri. Required when the mode is `callback`. The `callback_uri` property will be validated against the callback URIs that have been registered with the SLAS client. The callback URI _must_ be a `POST` endpoint because the token will be included in the body. Wildcards are not allowed in the callback_uri because this is a security risk that can expose the token. This is not considered an OAuth2 callback_url. * @param options.body.idp_name - The name of the 3rd party identity provider for the user ID * @param options.body.hint - Adding a `hint` query parameter with a value of `cross_device` will remove the need to have the code_challenge for password reset request. If the `hint` query parameter is used it must also be used in the password reset request. * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type void otherwise. */ authorizeWebauthnRegistration(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: authorizeWebauthnRegistrationBodyType; }>, rawResponse?: T): Promise; /** * This endpoint deletes a specific WebAuthn passkey credential for a user. The endpoint validates the Shopper JWT signature and ensures that the loginId, organizationId, and channel_id in the token match the values in the path and query parameters. The SLAS client must have the `sfcc.pwdless_login` scope to access this endpoint. This endpoint requires Shopper JWT authentication. * * If you would like to get a raw Response object use the other deletePasskeyCredential function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.parameters.channel_id - The channel (B2C Commerce site) that the user is associated with. * @param options.parameters.loginId - The login ID (username) of the user whose passkey credential is being deleted * @param options.parameters.credentialId - The unique identifier of the credential to delete * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * * @returns A promise of type void. */ deletePasskeyCredential(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; channel_id: string; loginId: string; credentialId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; }>): Promise; /** * This endpoint deletes a specific WebAuthn passkey credential for a user. The endpoint validates the Shopper JWT signature and ensures that the loginId, organizationId, and channel_id in the token match the values in the path and query parameters. The SLAS client must have the `sfcc.pwdless_login` scope to access this endpoint. This endpoint requires Shopper JWT authentication. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.parameters.channel_id - The channel (B2C Commerce site) that the user is associated with. * @param options.parameters.loginId - The login ID (username) of the user whose passkey credential is being deleted * @param options.parameters.credentialId - The unique identifier of the credential to delete * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type void otherwise. */ deletePasskeyCredential(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; channel_id: string; loginId: string; credentialId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; }>, rawResponse?: T): Promise; /** * This endpoint deletes a user's WebAuthn passkey information and all associated credentials. The endpoint validates the Shopper JWT signature and ensures that the loginId, organizationId, and channel_id in the token match the values in the path and query parameters. The SLAS client must have the `sfcc.pwdless_login` scope to access this endpoint. This endpoint requires Shopper JWT authentication. * * If you would like to get a raw Response object use the other deletePasskeyUser function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.parameters.channel_id - The channel (B2C Commerce site) that the user is associated with. * @param options.parameters.loginId - The login ID (username) of the user whose passkey information is being deleted * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * * @returns A promise of type void. */ deletePasskeyUser(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; channel_id: string; loginId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; }>): Promise; /** * This endpoint deletes a user's WebAuthn passkey information and all associated credentials. The endpoint validates the Shopper JWT signature and ensures that the loginId, organizationId, and channel_id in the token match the values in the path and query parameters. The SLAS client must have the `sfcc.pwdless_login` scope to access this endpoint. This endpoint requires Shopper JWT authentication. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.parameters.channel_id - The channel (B2C Commerce site) that the user is associated with. * @param options.parameters.loginId - The login ID (username) of the user whose passkey information is being deleted * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type void otherwise. */ deletePasskeyUser(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; channel_id: string; loginId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; }>, rawResponse?: T): Promise; /** * Completes the WebAuthn authentication process by verifying the assertion from the authenticator. Returns OAuth tokens upon successful authentication. The SLAS client must have the `sfcc.pwdless_login` scope to access this endpoint. * * If you would like to get a raw Response object use the other finishWebauthnAuthentication function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * * @returns A promise of type AuthenticateResult. */ finishWebauthnAuthentication(options: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: AuthenticateFinishRequest & CustomRequestBody; }>): Promise; /** * Completes the WebAuthn authentication process by verifying the assertion from the authenticator. Returns OAuth tokens upon successful authentication. The SLAS client must have the `sfcc.pwdless_login` scope to access this endpoint. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type AuthenticateResult otherwise. */ finishWebauthnAuthentication(options: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: AuthenticateFinishRequest & CustomRequestBody; }>, rawResponse?: T): Promise; /** * Completes the WebAuthn registration process by verifying the credential created by the authenticator. Stores the public key and credential information for future authentication. The SLAS client must have the `sfcc.pwdless_login` scope to access this endpoint. * * If you would like to get a raw Response object use the other finishWebauthnUserRegistration function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * * @returns A promise of type void. */ finishWebauthnUserRegistration(options: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: RegistrationFinishRequest & CustomRequestBody; }>): Promise; /** * Completes the WebAuthn registration process by verifying the credential created by the authenticator. Stores the public key and credential information for future authentication. The SLAS client must have the `sfcc.pwdless_login` scope to access this endpoint. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type void otherwise. */ finishWebauthnUserRegistration(options: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: RegistrationFinishRequest & CustomRequestBody; }>, rawResponse?: T): Promise; /** * This is the second step of the OAuth 2.1 authorization code flow. For a private client, an application is able to get an access token for the shopper through the back channel (a trusted server) by passing in the client credentials and the authorization code retrieved from the `authorize` endpoint. For a guest user, get the shopper JWT access token and a refresh token. This is where a client application is able to get an access token for the guest user through the back channel (a trusted server) by passing in the client credentials. For a public client using PKCE, an application passes a PKCE `code_verifier` that matches the `code_challenge` that was used to `authorize` the customer along with the authorization code. When refreshing the access token with a private client ID and client secret, the refresh token is _not_ regenerated. However, when refreshing the access token with a public client ID, the refresh token is _always_ regenerated. The old refresh token is voided with every refresh call, so the refresh token on the client must be replaced to always store the new refresh token. See the Body section for required parameters, including `grant_type` and others that depend on the value of `grant_type`. **Important**: As of July 31, 2024**, SLAS requires the `channel_id` query parameter in token requests. --- # Token Issuer Subject Construction & Constraints # The Issuer Subject (`isb`) claim of the issued JWT is a composite string that identifies the shopper session. It concatenates the identity origin (`uido`), login ID (`upn`), display name (`uidn`), guest customer ID (`gcid`, 26 chars), registered customer ID (`rcid`, 26 chars, when applicable), channel ID (`chid`), and any flow-specific values (`tsob`, `taob`, `agent`, `login`, `sesb`) as `key:value` pairs separated by `::`. **Constraint:** the assembled `isb` must not exceed **256 characters**. Exceeding this returns `400 BAD_REQUEST` with *"Issuer Subject length must be less than 256 characters"*. **Length calculation breakdown** (with `gcid`=26, `rcid`=26, `chid`≤100). Overhead = key chars + each key's trailing `:` + `::` separators between pairs. | Shape | Overhead | Fixed values | Remaining budget | |---|---|---|---| | Guest | 32 | gcid 26 + chid 100 = 126 | 98 | | Registered | 39 | gcid 26 + rcid 26 + chid 100 = 152 | 65 | | TSOB guest | 39 | gcid 26 + chid 100 = 126 | 91 - len(tsob) | | TSOB registered | 46 | gcid 26 + rcid 26 + chid 100 = 152 | 58 - len(tsob) | | Pwdless | 47 | gcid 26 + rcid 26 + chid 100 = 152 | 57 - len(login) | | SESB guest | 39 | gcid 26 + chid 100 = 126 | 91 - len(sesb) | | SESB registered | 46 | gcid 26 + rcid 26 + chid 100 = 152 | 58 - len(sesb) | | TAOB guest | 47 | gcid 26 + chid 100 = 126 | 83 - len(taob + agent) | | TAOB registered | 54 | gcid 26 + rcid 26 + chid 100 = 152 | 50 - len(taob + agent) | **Worst case (TAOB registered):** ``` 256 total - 54 overhead - 26 gcid - 26 rcid - 100 chid (allowed max) ---- 50 Then if taob = ta_ext_on_behalf_of: 50 - 19 = 31 Meaning only 31 characters remain for uido + upn + uidn + agent. ``` **Practical caps per variable sub-claim:** | Sub-claim | Description | Max length | |---|---|---| | `uido` | Identity origin | ~20 | | `upn` | Login ID / email | ~80 | | `uidn` | Display name (after `%3A` escaping) | ~60 | | `tsob` / `taob` | Trusted-system / trusted-agent hint | ~21 | | `agent` | Agent ID | ~32 | | `login` | Passwordless literal (e.g. `pwdless`) | short | | `sesb` | Session-bridge hint | short | | `chid` | Channel ID | 100 | **Notes:** - **Identity Origin Variance** — `uido` is a static IDP-configuration string (e.g. `ecom`, `google`, `Link_Brand_Production`). A longer origin reduces the budget available for user-supplied inputs. - **Double-Count Fallback** — if a shopper registers without a first and last name, `uidn` is generated from the email (prefix as first name, domain as last name), so the email is effectively counted **twice** (once as `upn`, once as `uidn`). Long emails are the most common cause of overflow. - Colons inside `uidn` are URL-encoded as `%3A`, which can further inflate its length. * * If you would like to get a raw Response object use the other getAccessToken function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.refresh_token - The long-term token used to refresh the short term access token. Required only with a grant type of `refresh_token`. * @param options.body.code - Authorization code from the OAuth 2.1 service received in the front channel that is used to get access tokens and refresh tokens. Required with a grant type of `authorization_code` and `session_bridge`. * @param options.body.usid - The shopper\'s unique identifier, if known. If not provided, a new USID is generated. * @param options.body.grant_type - * @param options.body.redirect_uri - The redirect URI that was used when getting the authorization code. A variety of URI formats and wildcards for host are supported, but app links like `airbnb://` or `fb://` are not. Examples of supported URIs: - `http://localhost:3000/callback` - `https://example.com/callback` - `com.example.app:redirect_uri_path` - ` *.subdomain.topleveldomain.com` * @param options.body.code_verifier - PKCE code verifier. Created by the client calling the `login` endpoint. The `code_verifier` should be a high entropy cryptographically random string with a minimum of 43 characters and a maximum of 128 characters. The `code_verifier` is optional when using a private client id for the token request. * @param options.body.client_id - The SLAS client ID. Required when the grant type is `authorization_code_pkce`. * @param options.body.channel_id - The channel (B2C Commerce site) that the user is associated with. **Important: We strongly recommended using the channel_id query parameter because it will be required in the future. **NOTE - As of July 31, 2024**, SLAS will be requiring the `channel_id` query parameter in token requests. * @param options.body.dnt - This is an optional parameter to set `Do Not Track` for the session. SLAS is making this available, but will not be used by B2C Commerce until after the 24.4 release. Values are: * `false` * `true` If not added the `dnt` value will default to `false`. * * @returns A promise of type TokenResponse. */ getAccessToken(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: getAccessTokenBodyType; }>): Promise; /** * This is the second step of the OAuth 2.1 authorization code flow. For a private client, an application is able to get an access token for the shopper through the back channel (a trusted server) by passing in the client credentials and the authorization code retrieved from the `authorize` endpoint. For a guest user, get the shopper JWT access token and a refresh token. This is where a client application is able to get an access token for the guest user through the back channel (a trusted server) by passing in the client credentials. For a public client using PKCE, an application passes a PKCE `code_verifier` that matches the `code_challenge` that was used to `authorize` the customer along with the authorization code. When refreshing the access token with a private client ID and client secret, the refresh token is _not_ regenerated. However, when refreshing the access token with a public client ID, the refresh token is _always_ regenerated. The old refresh token is voided with every refresh call, so the refresh token on the client must be replaced to always store the new refresh token. See the Body section for required parameters, including `grant_type` and others that depend on the value of `grant_type`. **Important**: As of July 31, 2024**, SLAS requires the `channel_id` query parameter in token requests. --- # Token Issuer Subject Construction & Constraints # The Issuer Subject (`isb`) claim of the issued JWT is a composite string that identifies the shopper session. It concatenates the identity origin (`uido`), login ID (`upn`), display name (`uidn`), guest customer ID (`gcid`, 26 chars), registered customer ID (`rcid`, 26 chars, when applicable), channel ID (`chid`), and any flow-specific values (`tsob`, `taob`, `agent`, `login`, `sesb`) as `key:value` pairs separated by `::`. **Constraint:** the assembled `isb` must not exceed **256 characters**. Exceeding this returns `400 BAD_REQUEST` with *"Issuer Subject length must be less than 256 characters"*. **Length calculation breakdown** (with `gcid`=26, `rcid`=26, `chid`≤100). Overhead = key chars + each key's trailing `:` + `::` separators between pairs. | Shape | Overhead | Fixed values | Remaining budget | |---|---|---|---| | Guest | 32 | gcid 26 + chid 100 = 126 | 98 | | Registered | 39 | gcid 26 + rcid 26 + chid 100 = 152 | 65 | | TSOB guest | 39 | gcid 26 + chid 100 = 126 | 91 - len(tsob) | | TSOB registered | 46 | gcid 26 + rcid 26 + chid 100 = 152 | 58 - len(tsob) | | Pwdless | 47 | gcid 26 + rcid 26 + chid 100 = 152 | 57 - len(login) | | SESB guest | 39 | gcid 26 + chid 100 = 126 | 91 - len(sesb) | | SESB registered | 46 | gcid 26 + rcid 26 + chid 100 = 152 | 58 - len(sesb) | | TAOB guest | 47 | gcid 26 + chid 100 = 126 | 83 - len(taob + agent) | | TAOB registered | 54 | gcid 26 + rcid 26 + chid 100 = 152 | 50 - len(taob + agent) | **Worst case (TAOB registered):** ``` 256 total - 54 overhead - 26 gcid - 26 rcid - 100 chid (allowed max) ---- 50 Then if taob = ta_ext_on_behalf_of: 50 - 19 = 31 Meaning only 31 characters remain for uido + upn + uidn + agent. ``` **Practical caps per variable sub-claim:** | Sub-claim | Description | Max length | |---|---|---| | `uido` | Identity origin | ~20 | | `upn` | Login ID / email | ~80 | | `uidn` | Display name (after `%3A` escaping) | ~60 | | `tsob` / `taob` | Trusted-system / trusted-agent hint | ~21 | | `agent` | Agent ID | ~32 | | `login` | Passwordless literal (e.g. `pwdless`) | short | | `sesb` | Session-bridge hint | short | | `chid` | Channel ID | 100 | **Notes:** - **Identity Origin Variance** — `uido` is a static IDP-configuration string (e.g. `ecom`, `google`, `Link_Brand_Production`). A longer origin reduces the budget available for user-supplied inputs. - **Double-Count Fallback** — if a shopper registers without a first and last name, `uidn` is generated from the email (prefix as first name, domain as last name), so the email is effectively counted **twice** (once as `upn`, once as `uidn`). Long emails are the most common cause of overflow. - Colons inside `uidn` are URL-encoded as `%3A`, which can further inflate its length. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.refresh_token - The long-term token used to refresh the short term access token. Required only with a grant type of `refresh_token`. * @param options.body.code - Authorization code from the OAuth 2.1 service received in the front channel that is used to get access tokens and refresh tokens. Required with a grant type of `authorization_code` and `session_bridge`. * @param options.body.usid - The shopper\'s unique identifier, if known. If not provided, a new USID is generated. * @param options.body.grant_type - * @param options.body.redirect_uri - The redirect URI that was used when getting the authorization code. A variety of URI formats and wildcards for host are supported, but app links like `airbnb://` or `fb://` are not. Examples of supported URIs: - `http://localhost:3000/callback` - `https://example.com/callback` - `com.example.app:redirect_uri_path` - ` *.subdomain.topleveldomain.com` * @param options.body.code_verifier - PKCE code verifier. Created by the client calling the `login` endpoint. The `code_verifier` should be a high entropy cryptographically random string with a minimum of 43 characters and a maximum of 128 characters. The `code_verifier` is optional when using a private client id for the token request. * @param options.body.client_id - The SLAS client ID. Required when the grant type is `authorization_code_pkce`. * @param options.body.channel_id - The channel (B2C Commerce site) that the user is associated with. **Important: We strongly recommended using the channel_id query parameter because it will be required in the future. **NOTE - As of July 31, 2024**, SLAS will be requiring the `channel_id` query parameter in token requests. * @param options.body.dnt - This is an optional parameter to set `Do Not Track` for the session. SLAS is making this available, but will not be used by B2C Commerce until after the 24.4 release. Values are: * `false` * `true` If not added the `dnt` value will default to `false`. * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type TokenResponse otherwise. */ getAccessToken(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: getAccessTokenBodyType; }>, rawResponse?: T): Promise; /** * The `/jwks` endpoint provides a JSON Web Key Set (JWKS) that includes current, past, and future public keys. These keys allow clients to validate the Shopper JSON Web Token (JWT) issued by SLAS, ensuring that no tampering with the token has occurred. Every SLAS JWT that is passed into SLAS, SCAPI, or OCAPI is always validated and is rejected if the signature validation does not match. To optimize performance, the `/jwks` endpoint is limited to 25 calls per minute, so we recommended caching the JWKS keys and refresh them only when necessary, instead of making frequent requests. Typically, the JWKs endpoint can be used once per DAY. For additional information on using JWKS, see https://developer.salesforce.com/docs/commerce/commerce-api/guide/slas-validate-jwt-with-jwks.html. * * If you would like to get a raw Response object use the other getJwksUri function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * * @returns A promise of type object. */ getJwksUri(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; }>): Promise; /** * The `/jwks` endpoint provides a JSON Web Key Set (JWKS) that includes current, past, and future public keys. These keys allow clients to validate the Shopper JSON Web Token (JWT) issued by SLAS, ensuring that no tampering with the token has occurred. Every SLAS JWT that is passed into SLAS, SCAPI, or OCAPI is always validated and is rejected if the signature validation does not match. To optimize performance, the `/jwks` endpoint is limited to 25 calls per minute, so we recommended caching the JWKS keys and refresh them only when necessary, instead of making frequent requests. Typically, the JWKs endpoint can be used once per DAY. For additional information on using JWKS, see https://developer.salesforce.com/docs/commerce/commerce-api/guide/slas-validate-jwt-with-jwks.html. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type object otherwise. */ getJwksUri(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; }>, rawResponse?: T): Promise; /** * This endpoint retrieves a user's WebAuthn passkey information including all associated credentials. It returns the user's profile information along with a list of all registered passkey credentials. The SLAS client must have the `sfcc.pwdless_login` scope to access this endpoint. This endpoint requires Shopper JWT authentication. * * If you would like to get a raw Response object use the other getPasskeyUserByLoginId function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.parameters.channel_id - The channel (B2C Commerce site) that the user is associated with. * @param options.parameters.loginId - The login ID (username) of the user whose passkey information is being retrieved * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * * @returns A promise of type PasskeyUser. */ getPasskeyUserByLoginId(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; channel_id: string; loginId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; }>): Promise; /** * This endpoint retrieves a user's WebAuthn passkey information including all associated credentials. It returns the user's profile information along with a list of all registered passkey credentials. The SLAS client must have the `sfcc.pwdless_login` scope to access this endpoint. This endpoint requires Shopper JWT authentication. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.parameters.channel_id - The channel (B2C Commerce site) that the user is associated with. * @param options.parameters.loginId - The login ID (username) of the user whose passkey information is being retrieved * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type PasskeyUser otherwise. */ getPasskeyUserByLoginId(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; channel_id: string; loginId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; }>, rawResponse?: T): Promise; /** * This endpoint issues a shopper JSON Web Token (JWT) using a passwordless login token. It enables authentication flows where traditional username/password combinations are not required, supporting alternative authentication methods. --- # Token Issuer Subject Construction & Constraints # The Issuer Subject (`isb`) claim of the issued JWT is a composite string that identifies the shopper session. It concatenates the identity origin (`uido`), login ID (`upn`), display name (`uidn`), guest customer ID (`gcid`, 26 chars), registered customer ID (`rcid`, 26 chars, when applicable), channel ID (`chid`), and any flow-specific values (`tsob`, `taob`, `agent`, `login`, `sesb`) as `key:value` pairs separated by `::`. **Constraint:** the assembled `isb` must not exceed **256 characters**. Exceeding this returns `400 BAD_REQUEST` with *"Issuer Subject length must be less than 256 characters"*. **Length calculation breakdown** (with `gcid`=26, `rcid`=26, `chid`≤100). Overhead = key chars + each key's trailing `:` + `::` separators between pairs. | Shape | Overhead | Fixed values | Remaining budget | |---|---|---|---| | Guest | 32 | gcid 26 + chid 100 = 126 | 98 | | Registered | 39 | gcid 26 + rcid 26 + chid 100 = 152 | 65 | | TSOB guest | 39 | gcid 26 + chid 100 = 126 | 91 - len(tsob) | | TSOB registered | 46 | gcid 26 + rcid 26 + chid 100 = 152 | 58 - len(tsob) | | Pwdless | 47 | gcid 26 + rcid 26 + chid 100 = 152 | 57 - len(login) | | SESB guest | 39 | gcid 26 + chid 100 = 126 | 91 - len(sesb) | | SESB registered | 46 | gcid 26 + rcid 26 + chid 100 = 152 | 58 - len(sesb) | | TAOB guest | 47 | gcid 26 + chid 100 = 126 | 83 - len(taob + agent) | | TAOB registered | 54 | gcid 26 + rcid 26 + chid 100 = 152 | 50 - len(taob + agent) | **Worst case (TAOB registered):** ``` 256 total - 54 overhead - 26 gcid - 26 rcid - 100 chid (allowed max) ---- 50 Then if taob = ta_ext_on_behalf_of: 50 - 19 = 31 Meaning only 31 characters remain for uido + upn + uidn + agent. ``` **Practical caps per variable sub-claim:** | Sub-claim | Description | Max length | |---|---|---| | `uido` | Identity origin | ~20 | | `upn` | Login ID / email | ~80 | | `uidn` | Display name (after `%3A` escaping) | ~60 | | `tsob` / `taob` | Trusted-system / trusted-agent hint | ~21 | | `agent` | Agent ID | ~32 | | `login` | Passwordless literal (e.g. `pwdless`) | short | | `sesb` | Session-bridge hint | short | | `chid` | Channel ID | 100 | **Notes:** - **Identity Origin Variance** — `uido` is a static IdP-configuration string (e.g. `ecom`, `google`, `Link_Brand_Production`). A longer origin reduces the budget available for user-supplied inputs. - **Double-Count Fallback** — if a shopper registers without a first and last name, `uidn` is generated from the email (prefix as first name, domain as last name), so the email is effectively counted **twice** (once as `upn`, once as `uidn`). Long emails are the most common cause of overflow. - Colons inside `uidn` are URL-encoded as `%3A`, which can further inflate its length. * * If you would like to get a raw Response object use the other getPasswordLessAccessToken function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.grant_type - Grant Type * @param options.body.hint - Passwordless hint. Use `pwdless_login`. * @param options.body.pwdless_login_token - Passwordless login token that was created from the user ID. * @param options.body.client_id - The public client ID. * @param options.body.code_verifier - PKCE code verifier. Created by the client. The `code_challenge` is created by SHA256 hashing the `code_verifier` and Base64 encoding the resulting hash. The `code_verifier` should be a high entropy cryptographically random string with a minimum of 43 characters and a maximum of 128 characters. * @param options.body.login_id - The ID used by the shopper for password token request. When provided, login_id must exactly match the ID used during passwordless login. ex. If passwordless login used `samantha.sampleson@example.com`, but the passwordless login token request provides `sam.sampleson@example.com`, the request fails due to mismatch. * * @returns A promise of type TokenResponse. */ getPasswordLessAccessToken(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: getPasswordLessAccessTokenBodyType; }>): Promise; /** * This endpoint issues a shopper JSON Web Token (JWT) using a passwordless login token. It enables authentication flows where traditional username/password combinations are not required, supporting alternative authentication methods. --- # Token Issuer Subject Construction & Constraints # The Issuer Subject (`isb`) claim of the issued JWT is a composite string that identifies the shopper session. It concatenates the identity origin (`uido`), login ID (`upn`), display name (`uidn`), guest customer ID (`gcid`, 26 chars), registered customer ID (`rcid`, 26 chars, when applicable), channel ID (`chid`), and any flow-specific values (`tsob`, `taob`, `agent`, `login`, `sesb`) as `key:value` pairs separated by `::`. **Constraint:** the assembled `isb` must not exceed **256 characters**. Exceeding this returns `400 BAD_REQUEST` with *"Issuer Subject length must be less than 256 characters"*. **Length calculation breakdown** (with `gcid`=26, `rcid`=26, `chid`≤100). Overhead = key chars + each key's trailing `:` + `::` separators between pairs. | Shape | Overhead | Fixed values | Remaining budget | |---|---|---|---| | Guest | 32 | gcid 26 + chid 100 = 126 | 98 | | Registered | 39 | gcid 26 + rcid 26 + chid 100 = 152 | 65 | | TSOB guest | 39 | gcid 26 + chid 100 = 126 | 91 - len(tsob) | | TSOB registered | 46 | gcid 26 + rcid 26 + chid 100 = 152 | 58 - len(tsob) | | Pwdless | 47 | gcid 26 + rcid 26 + chid 100 = 152 | 57 - len(login) | | SESB guest | 39 | gcid 26 + chid 100 = 126 | 91 - len(sesb) | | SESB registered | 46 | gcid 26 + rcid 26 + chid 100 = 152 | 58 - len(sesb) | | TAOB guest | 47 | gcid 26 + chid 100 = 126 | 83 - len(taob + agent) | | TAOB registered | 54 | gcid 26 + rcid 26 + chid 100 = 152 | 50 - len(taob + agent) | **Worst case (TAOB registered):** ``` 256 total - 54 overhead - 26 gcid - 26 rcid - 100 chid (allowed max) ---- 50 Then if taob = ta_ext_on_behalf_of: 50 - 19 = 31 Meaning only 31 characters remain for uido + upn + uidn + agent. ``` **Practical caps per variable sub-claim:** | Sub-claim | Description | Max length | |---|---|---| | `uido` | Identity origin | ~20 | | `upn` | Login ID / email | ~80 | | `uidn` | Display name (after `%3A` escaping) | ~60 | | `tsob` / `taob` | Trusted-system / trusted-agent hint | ~21 | | `agent` | Agent ID | ~32 | | `login` | Passwordless literal (e.g. `pwdless`) | short | | `sesb` | Session-bridge hint | short | | `chid` | Channel ID | 100 | **Notes:** - **Identity Origin Variance** — `uido` is a static IdP-configuration string (e.g. `ecom`, `google`, `Link_Brand_Production`). A longer origin reduces the budget available for user-supplied inputs. - **Double-Count Fallback** — if a shopper registers without a first and last name, `uidn` is generated from the email (prefix as first name, domain as last name), so the email is effectively counted **twice** (once as `upn`, once as `uidn`). Long emails are the most common cause of overflow. - Colons inside `uidn` are URL-encoded as `%3A`, which can further inflate its length. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.grant_type - Grant Type * @param options.body.hint - Passwordless hint. Use `pwdless_login`. * @param options.body.pwdless_login_token - Passwordless login token that was created from the user ID. * @param options.body.client_id - The public client ID. * @param options.body.code_verifier - PKCE code verifier. Created by the client. The `code_challenge` is created by SHA256 hashing the `code_verifier` and Base64 encoding the resulting hash. The `code_verifier` should be a high entropy cryptographically random string with a minimum of 43 characters and a maximum of 128 characters. * @param options.body.login_id - The ID used by the shopper for password token request. When provided, login_id must exactly match the ID used during passwordless login. ex. If passwordless login used `samantha.sampleson@example.com`, but the passwordless login token request provides `sam.sampleson@example.com`, the request fails due to mismatch. * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type TokenResponse otherwise. */ getPasswordLessAccessToken(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: getPasswordLessAccessTokenBodyType; }>, rawResponse?: T): Promise; /** * This endpoint initiates the password reset process for a customer by requesting a password reset token. The token is delivered through the configured delivery mode (email, SMS, etc.) and can be used with the password/action endpoint to set a new password. * * If you would like to get a raw Response object use the other getPasswordResetToken function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.user_id - User ID for logging in. This is the id that is used to log into SFCC. * @param options.body.mode - Password Action delivery modes * @param options.body.channel_id - The channel (B2C Commerce site) that the user is associated with. * @param options.body.locale - The locale of the template. Required when the mode is `email` or `sms`. * @param options.body.client_id - -| The public client ID. Requires setting `grant_type` to `passwordless_login_pkce`. When using the `hint` query parameter either a public or private client ID can be used. * @param options.body.code_challenge - PKCE code challenge. Created by the client. The `code_challenge` is created by SHA256 hashing the `code_verifier` and Base64 encoding the resulting hash. The `code_verifier` should be a high entropy cryptographically random string with a minimum of 43 characters and a maximum of 128 characters. Requires setting `grant_type` to `passwordless_login_pkce` * @param options.body.callback_uri - The callback uri. Required when the mode is `callback`. The `callback_uri` property will be validated against the callback URIs that have been registered with the SLAS client. The callback URI _must_ be a `POST` endpoint because the token will be included in the body. Wildcards are not allowed in the callback_uri because this is a security risk that can expose the token. This is not considered an OAuth2 callback_url. * @param options.body.idp_name - The name of the 3rd party identity provider for the user ID * @param options.body.hint - Adding a `hint` query parameter with a value of `cross_device` will remove the need to have the code_challenge for password reset request. If the `hint` query parameter is used it must also be used in the password reset request. * * @returns A promise of type void. */ getPasswordResetToken(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: getPasswordResetTokenBodyType; }>): Promise; /** * This endpoint initiates the password reset process for a customer by requesting a password reset token. The token is delivered through the configured delivery mode (email, SMS, etc.) and can be used with the password/action endpoint to set a new password. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.user_id - User ID for logging in. This is the id that is used to log into SFCC. * @param options.body.mode - Password Action delivery modes * @param options.body.channel_id - The channel (B2C Commerce site) that the user is associated with. * @param options.body.locale - The locale of the template. Required when the mode is `email` or `sms`. * @param options.body.client_id - -| The public client ID. Requires setting `grant_type` to `passwordless_login_pkce`. When using the `hint` query parameter either a public or private client ID can be used. * @param options.body.code_challenge - PKCE code challenge. Created by the client. The `code_challenge` is created by SHA256 hashing the `code_verifier` and Base64 encoding the resulting hash. The `code_verifier` should be a high entropy cryptographically random string with a minimum of 43 characters and a maximum of 128 characters. Requires setting `grant_type` to `passwordless_login_pkce` * @param options.body.callback_uri - The callback uri. Required when the mode is `callback`. The `callback_uri` property will be validated against the callback URIs that have been registered with the SLAS client. The callback URI _must_ be a `POST` endpoint because the token will be included in the body. Wildcards are not allowed in the callback_uri because this is a security risk that can expose the token. This is not considered an OAuth2 callback_url. * @param options.body.idp_name - The name of the 3rd party identity provider for the user ID * @param options.body.hint - Adding a `hint` query parameter with a value of `cross_device` will remove the need to have the code_challenge for password reset request. If the `hint` query parameter is used it must also be used in the password reset request. * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type void otherwise. */ getPasswordResetToken(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: getPasswordResetTokenBodyType; }>, rawResponse?: T): Promise; /** * For public client ID requests, you must set the grant_type to `session_bridge`. For private client_id and secret, you must set the grant_type to `client_credentials` along with a basic authorization header. **DEPRECATED** - As of January 31, 2024, SLAS no longer supports the SESB `dwsid` parameter for `guest` users for `session-bridge/token` calls. We recommended you transition to using a SESB `dwsgst` token. The `dwsid` is still needed for `registered` user `session-bridge/token` calls. **NOTE:** The registered customer Json Web Token (JWT) is available in B2C Commerce versions 25.4 and later. * * If you would like to get a raw Response object use the other getSessionBridgeAccessToken function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.code - Authorization code returned from session bridge authorization received in the front channel that is used to get session bridge access tokens and refresh tokens. Required with a grant type of `session_bridge`. The SLAS client must have the `sfcc.session_bridge` scope to request a session bridge token. * @param options.body.client_id - The SLAS public client ID for use with PKCE requests. This is a required parameter when using a public client. * @param options.body.channel_id - The channel (B2C Commerce site) that the user is associated with. * @param options.body.code_verifier - PKCE code verifier. Created by the caller. This is a required parameter when using a public client. The `code_challenge` is created by SHA256 hashing the `code_verifier` and Base64 encoding the resulting hash. The `code_verifier` should be a high entropy cryptographically random string with a minimum of 43 characters and a maximum of 128 characters. * @param options.body.dwsid - Cookie passed back from the \'/authorize\' endpoint call for session bridge. This parameter is optional and not needed if using the `dwsgst` parameter. **DEPRECATED** - As of January 31, 2024, SLAS will no longer support the SESB `dwsid` parameter for `guest` users for `session-bridge/token` calls. It is recommended to transition over to using a SESB `dwsgst` token. The `dwsid` will still be needed for `registered` user session-bridge/token calls. * @param options.body.grant_type - Grant Type * @param options.body.login_id - The ID of the shopper for session bridge access. If requesting a token for a guest user set login_id to `guest`. * @param options.body.dwsgst - Signed guest Json Web Token (JWT) that was obtained from B2C Commerce. This parameter is optional and not needed if using the guest `dwsid` parameter. * @param options.body.dwsrst - Signed registered customer Json Web Token (JWT) that was obtained from B2C Commerce. This parameter is optional and not needed if using the registered user `dwsid` parameter. **NOTE:** The registered customer Json Web Token (JWT) will be available in ECOM versions 25.4 and higher. * @param options.body.usid - The unique shopper ID. Returned when from session bridge authorization. * @param options.body.dnt - This is an optional parameter to set `Do Not Track` for the session. SLAS is making this available, but will not be used by B2C Commerce until after the 24.4 release. Values are: * `false` * `true` If not added the `dnt` value will default to `false`. * * @returns A promise of type TokenResponse. */ getSessionBridgeAccessToken(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: getSessionBridgeAccessTokenBodyType; }>): Promise; /** * For public client ID requests, you must set the grant_type to `session_bridge`. For private client_id and secret, you must set the grant_type to `client_credentials` along with a basic authorization header. **DEPRECATED** - As of January 31, 2024, SLAS no longer supports the SESB `dwsid` parameter for `guest` users for `session-bridge/token` calls. We recommended you transition to using a SESB `dwsgst` token. The `dwsid` is still needed for `registered` user `session-bridge/token` calls. **NOTE:** The registered customer Json Web Token (JWT) is available in B2C Commerce versions 25.4 and later. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.code - Authorization code returned from session bridge authorization received in the front channel that is used to get session bridge access tokens and refresh tokens. Required with a grant type of `session_bridge`. The SLAS client must have the `sfcc.session_bridge` scope to request a session bridge token. * @param options.body.client_id - The SLAS public client ID for use with PKCE requests. This is a required parameter when using a public client. * @param options.body.channel_id - The channel (B2C Commerce site) that the user is associated with. * @param options.body.code_verifier - PKCE code verifier. Created by the caller. This is a required parameter when using a public client. The `code_challenge` is created by SHA256 hashing the `code_verifier` and Base64 encoding the resulting hash. The `code_verifier` should be a high entropy cryptographically random string with a minimum of 43 characters and a maximum of 128 characters. * @param options.body.dwsid - Cookie passed back from the \'/authorize\' endpoint call for session bridge. This parameter is optional and not needed if using the `dwsgst` parameter. **DEPRECATED** - As of January 31, 2024, SLAS will no longer support the SESB `dwsid` parameter for `guest` users for `session-bridge/token` calls. It is recommended to transition over to using a SESB `dwsgst` token. The `dwsid` will still be needed for `registered` user session-bridge/token calls. * @param options.body.grant_type - Grant Type * @param options.body.login_id - The ID of the shopper for session bridge access. If requesting a token for a guest user set login_id to `guest`. * @param options.body.dwsgst - Signed guest Json Web Token (JWT) that was obtained from B2C Commerce. This parameter is optional and not needed if using the guest `dwsid` parameter. * @param options.body.dwsrst - Signed registered customer Json Web Token (JWT) that was obtained from B2C Commerce. This parameter is optional and not needed if using the registered user `dwsid` parameter. **NOTE:** The registered customer Json Web Token (JWT) will be available in ECOM versions 25.4 and higher. * @param options.body.usid - The unique shopper ID. Returned when from session bridge authorization. * @param options.body.dnt - This is an optional parameter to set `Do Not Track` for the session. SLAS is making this available, but will not be used by B2C Commerce until after the 24.4 release. Values are: * `false` * `true` If not added the `dnt` value will default to `false`. * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type TokenResponse otherwise. */ getSessionBridgeAccessToken(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: getSessionBridgeAccessTokenBodyType; }>, rawResponse?: T): Promise; /** * If using a SLAS private client ID, you must also use an `_sfdc_client_auth` header. The value of the `_sfdc_client_auth` header must be a Base64-encoded string. The string is composed of a SLAS private client ID and client secret, separated by a colon (`:`). For example, `privateClientId:privateClientsecret` becomes `cHJpdmF0ZUNsaWVudElkOnByaXZhdGVDbGllbnRzZWNyZXQ=` after Base64 encoding. * * If you would like to get a raw Response object use the other getTrustedAgentAccessToken function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.agent_id - The ID of the merchant. If passed in, the `agent_id` will be validated using the SUB claim in the response from Account Manager. This is an optional parameter unless the request is for a Trusted Agent on Behalf then `agent_id` is required. * @param options.body.client_id - The SLAS public client ID or SLAS private client ID for use with trusted-system requests. The `client_id` is not needed if a using a SLAS private `client_id` and the `_sfdc_client_auth` header. * @param options.body.channel_id - The channel (B2C Commerce site) that the user is associated with. * @param options.body.code_verifier - PKCE code verifier. Created by the caller. The `code_challenge` is created by SHA256 hashing the `code_verifier` and Base64 encoding the resulting hash. The `code_verifier` should be a high entropy cryptographically random string with a minimum of 43 characters and a maximum of 128 characters. The `code_verifier` is not needed if a using a SLAS private `client_id` and the `_sfdc_client_auth` header. * @param options.body.grant_type - Grant Type * @param options.body.login_id - The ID is the shopper for trusted agent access. For TAOB Guest the `login_id` must be set to `Guest`. * @param options.body.idp_origin - The IDP that the user is associated with. For TAOB Guest the `idp_origin` parameter should be `slas`. If set to any other IDP origin a 400 Bad Request will be returned. * @param options.body.usid - The shopper\'s unique identifier, if known. If not provided, a new USID is generated. * @param options.body.dnt - This is an optional parameter to set `Do Not Track` for the session. SLAS is making this available, but will not be used by B2C Commerce until after the 24.4 release. Values are: * `false` * `true` If not added the `dnt` value will default to `true` Note: The default value for `dnt` is set to `true` for all TAOB flows. This is opposite from other SLAS token requests. * @param options.body.state - This is an optional parameter to set state for the trusted agent session. If the `state` parameter is used it will be validated and a 400 Bad Request will be returned if missing or invalid. For TAOB Guest you must pass the `state` parameter to transfer the state from the TAOB Guest authorization call to the token call. The `state` parameter value is returned with the authorization code in the response url from the TAOB guest authorization call, for example: `.../taob/callback?code=HETXpvg5LKBNIHjDTWkRrf2MLVU&state=taob.gst.7bc7fb7f-e646-44fd-bc73-dfd5c3c9019b`. You would use `taob.gst.7bc7fb7f-e646-44fd-bc73-dfd5c3c9019b` for the `state` value in the TAOB request. * * @returns A promise of type TokenResponse. */ getTrustedAgentAccessToken(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: getTrustedAgentAccessTokenBodyType; }>): Promise; /** * If using a SLAS private client ID, you must also use an `_sfdc_client_auth` header. The value of the `_sfdc_client_auth` header must be a Base64-encoded string. The string is composed of a SLAS private client ID and client secret, separated by a colon (`:`). For example, `privateClientId:privateClientsecret` becomes `cHJpdmF0ZUNsaWVudElkOnByaXZhdGVDbGllbnRzZWNyZXQ=` after Base64 encoding. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.agent_id - The ID of the merchant. If passed in, the `agent_id` will be validated using the SUB claim in the response from Account Manager. This is an optional parameter unless the request is for a Trusted Agent on Behalf then `agent_id` is required. * @param options.body.client_id - The SLAS public client ID or SLAS private client ID for use with trusted-system requests. The `client_id` is not needed if a using a SLAS private `client_id` and the `_sfdc_client_auth` header. * @param options.body.channel_id - The channel (B2C Commerce site) that the user is associated with. * @param options.body.code_verifier - PKCE code verifier. Created by the caller. The `code_challenge` is created by SHA256 hashing the `code_verifier` and Base64 encoding the resulting hash. The `code_verifier` should be a high entropy cryptographically random string with a minimum of 43 characters and a maximum of 128 characters. The `code_verifier` is not needed if a using a SLAS private `client_id` and the `_sfdc_client_auth` header. * @param options.body.grant_type - Grant Type * @param options.body.login_id - The ID is the shopper for trusted agent access. For TAOB Guest the `login_id` must be set to `Guest`. * @param options.body.idp_origin - The IDP that the user is associated with. For TAOB Guest the `idp_origin` parameter should be `slas`. If set to any other IDP origin a 400 Bad Request will be returned. * @param options.body.usid - The shopper\'s unique identifier, if known. If not provided, a new USID is generated. * @param options.body.dnt - This is an optional parameter to set `Do Not Track` for the session. SLAS is making this available, but will not be used by B2C Commerce until after the 24.4 release. Values are: * `false` * `true` If not added the `dnt` value will default to `true` Note: The default value for `dnt` is set to `true` for all TAOB flows. This is opposite from other SLAS token requests. * @param options.body.state - This is an optional parameter to set state for the trusted agent session. If the `state` parameter is used it will be validated and a 400 Bad Request will be returned if missing or invalid. For TAOB Guest you must pass the `state` parameter to transfer the state from the TAOB Guest authorization call to the token call. The `state` parameter value is returned with the authorization code in the response url from the TAOB guest authorization call, for example: `.../taob/callback?code=HETXpvg5LKBNIHjDTWkRrf2MLVU&state=taob.gst.7bc7fb7f-e646-44fd-bc73-dfd5c3c9019b`. You would use `taob.gst.7bc7fb7f-e646-44fd-bc73-dfd5c3c9019b` for the `state` value in the TAOB request. * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type TokenResponse otherwise. */ getTrustedAgentAccessToken(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: getTrustedAgentAccessTokenBodyType; }>, rawResponse?: T): Promise; /** * This endpoint enables trusted agents (such as customer service representatives or merchants) to obtain authorization tokens that allow them to act on behalf of registered customers. This facilitates customer support scenarios where agents need secure access to customer accounts. * * If you would like to get a raw Response object use the other getTrustedAgentAuthorizationToken function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.parameters.client_id - The SLAS public client ID or SLAS private client ID for use with trusted-agent requests. When using a private client ID a PKCE code challenge is not required. * @param options.parameters.channel_id - The channel (B2C Commerce site) that the user is associated with. * @param options.parameters.login_id - The ID of the shopper for trusted agent access. For TAOB Guest the `login_id` must be set to `Guest`. * @param options.parameters.idp_origin - The IDP that the shopper is associated with. For TAOB Guest the `idp_origin` must be set to `slas`. This is standard for SLAS Guest requests. If any other `idp_origin` value is used, SLAS returns a bad request. * @param options.parameters.redirect_uri - The redirect for Account Manager to redirect to. A variety of URI formats and wildcard for host are supported, but app links like `airbnb://` or `fb://` are not. Examples of supported URIs: - `http://localhost:3000/callback` - `https://example.com/callback` - `com.example.app:redirect_uri_path` - ` *.subdomain.topleveldomain.com` * @param options.parameters.response_type - Must be `code`. Indicates that the caller wants an authorization code. * @param options.parameters.code_challenge - PKCE code challenge. Created by the caller. The `code_challenge` is created by SHA256 hashing the `code_verifier` and Base64 encoding the resulting hash. The `code_verifier` should be a high entropy cryptographically random string with a minimum of 43 characters and a maximum of 128 characters. The *`code_challenge` and 'code_verifier'* are required if a using SLAS public `client_id`. * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * * @returns A promise of type void. */ getTrustedAgentAuthorizationToken(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; client_id: string; channel_id: string; login_id: string; idp_origin: string; redirect_uri: string; response_type: GetTrustedAgentAuthorizationTokenResponseTypeEnum; code_challenge?: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; }>): Promise; /** * This endpoint enables trusted agents (such as customer service representatives or merchants) to obtain authorization tokens that allow them to act on behalf of registered customers. This facilitates customer support scenarios where agents need secure access to customer accounts. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.parameters.client_id - The SLAS public client ID or SLAS private client ID for use with trusted-agent requests. When using a private client ID a PKCE code challenge is not required. * @param options.parameters.channel_id - The channel (B2C Commerce site) that the user is associated with. * @param options.parameters.login_id - The ID of the shopper for trusted agent access. For TAOB Guest the `login_id` must be set to `Guest`. * @param options.parameters.idp_origin - The IDP that the shopper is associated with. For TAOB Guest the `idp_origin` must be set to `slas`. This is standard for SLAS Guest requests. If any other `idp_origin` value is used, SLAS returns a bad request. * @param options.parameters.redirect_uri - The redirect for Account Manager to redirect to. A variety of URI formats and wildcard for host are supported, but app links like `airbnb://` or `fb://` are not. Examples of supported URIs: - `http://localhost:3000/callback` - `https://example.com/callback` - `com.example.app:redirect_uri_path` - ` *.subdomain.topleveldomain.com` * @param options.parameters.response_type - Must be `code`. Indicates that the caller wants an authorization code. * @param options.parameters.code_challenge - PKCE code challenge. Created by the caller. The `code_challenge` is created by SHA256 hashing the `code_verifier` and Base64 encoding the resulting hash. The `code_verifier` should be a high entropy cryptographically random string with a minimum of 43 characters and a maximum of 128 characters. The *`code_challenge` and 'code_verifier'* are required if a using SLAS public `client_id`. * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type void otherwise. */ getTrustedAgentAuthorizationToken(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; client_id: string; channel_id: string; login_id: string; idp_origin: string; redirect_uri: string; response_type: GetTrustedAgentAuthorizationTokenResponseTypeEnum; code_challenge?: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; }>, rawResponse?: T): Promise; /** * The SLAS client must have the `sfcc.ts_ext_on_behalf_of` scope to access this endpoint. For trusted-system requests, you can use a basic authorization header that includes a SLAS private client ID and SLAS private client secret instead of the bearer token. For trusted-system requests, you cannot use SLAS public client_ids. --- # Token Issuer Subject Construction & Constraints # The Issuer Subject (`isb`) claim of the issued JWT is a composite string that identifies the shopper session. It concatenates the identity origin (`uido`), login ID (`upn`), display name (`uidn`), guest customer ID (`gcid`, 26 chars), registered customer ID (`rcid`, 26 chars, when applicable), channel ID (`chid`), and any flow-specific values (`tsob`, `taob`, `agent`, `login`, `sesb`) as `key:value` pairs separated by `::`. **Constraint:** the assembled `isb` must not exceed **256 characters**. Exceeding this returns `400 BAD_REQUEST` with *"Issuer Subject length must be less than 256 characters"*. **Length calculation breakdown** (with `gcid`=26, `rcid`=26, `chid`≤100). Overhead = key chars + each key's trailing `:` + `::` separators between pairs. | Shape | Overhead | Fixed values | Remaining budget | |---|---|---|---| | Guest | 32 | gcid 26 + chid 100 = 126 | 98 | | Registered | 39 | gcid 26 + rcid 26 + chid 100 = 152 | 65 | | TSOB guest | 39 | gcid 26 + chid 100 = 126 | 91 - len(tsob) | | TSOB registered | 46 | gcid 26 + rcid 26 + chid 100 = 152 | 58 - len(tsob) | | Pwdless | 47 | gcid 26 + rcid 26 + chid 100 = 152 | 57 - len(login) | | SESB guest | 39 | gcid 26 + chid 100 = 126 | 91 - len(sesb) | | SESB registered | 46 | gcid 26 + rcid 26 + chid 100 = 152 | 58 - len(sesb) | | TAOB guest | 47 | gcid 26 + chid 100 = 126 | 83 - len(taob + agent) | | TAOB registered | 54 | gcid 26 + rcid 26 + chid 100 = 152 | 50 - len(taob + agent) | **Worst case (TAOB registered):** ``` 256 total - 54 overhead - 26 gcid - 26 rcid - 100 chid (allowed max) ---- 50 Then if taob = ta_ext_on_behalf_of: 50 - 19 = 31 Meaning only 31 characters remain for uido + upn + uidn + agent. ``` **Practical caps per variable sub-claim:** | Sub-claim | Description | Max length | |---|---|---| | `uido` | Identity origin | ~20 | | `upn` | Login ID / email | ~80 | | `uidn` | Display name (after `%3A` escaping) | ~60 | | `tsob` / `taob` | Trusted-system / trusted-agent hint | ~21 | | `agent` | Agent ID | ~32 | | `login` | Passwordless literal (e.g. `pwdless`) | short | | `sesb` | Session-bridge hint | short | | `chid` | Channel ID | 100 | **Notes:** - **Identity Origin Variance** — `uido` is a static IDP-configuration string (e.g. `ecom`, `google`, `Link_Brand_Production`). A longer origin reduces the budget available for user-supplied inputs. - **Double-Count Fallback** — if a shopper registers without a first and last name, `uidn` is generated from the email (prefix as first name, domain as last name), so the email is effectively counted **twice** (once as `upn`, once as `uidn`). Long emails are the most common cause of overflow. - Colons inside `uidn` are URL-encoded as `%3A`, which can further inflate its length. * * If you would like to get a raw Response object use the other getTrustedSystemAccessToken function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.usid - The shopper\'s unique identifier, if known. If not provided, a new USID is generated. * @param options.body.grant_type - Grant Type * @param options.body.hint - Type of system used for Trusted System On Behalf of requests. * @param options.body.login_id - The ID used by the shopper for trusted system access. If set to `guest`, a token is returned for a guest user. * @param options.body.idp_origin - IDPs that work with SLAS. Use `ecom` when using B2C Commerce is the identity provider. * @param options.body.client_id - The SLAS public client ID for use with trusted-system requests. * @param options.body.channel_id - The channel (ECOM site) that the user is associated with. * @param options.body.email_id - The email address for the shopper that is used for trusted-system requests. If not provided, `login_id` is used instead. * @param options.body.dnt - This is an optional parameter to set `Do Not Track` for the session. SLAS is making this available, but will not be used by B2C Commerce until after the 24.4 release. Values are: * `false` * `true` If not added the `dnt` value will default to `false`. Note: The default value for `dnt` is set to `false` for SLAS token requests except for Trusted Agent token request. For Trusted Agent token requests the default value for `dnt` is `true`. * * @returns A promise of type TokenResponse. */ getTrustedSystemAccessToken(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: getTrustedSystemAccessTokenBodyType; }>): Promise; /** * The SLAS client must have the `sfcc.ts_ext_on_behalf_of` scope to access this endpoint. For trusted-system requests, you can use a basic authorization header that includes a SLAS private client ID and SLAS private client secret instead of the bearer token. For trusted-system requests, you cannot use SLAS public client_ids. --- # Token Issuer Subject Construction & Constraints # The Issuer Subject (`isb`) claim of the issued JWT is a composite string that identifies the shopper session. It concatenates the identity origin (`uido`), login ID (`upn`), display name (`uidn`), guest customer ID (`gcid`, 26 chars), registered customer ID (`rcid`, 26 chars, when applicable), channel ID (`chid`), and any flow-specific values (`tsob`, `taob`, `agent`, `login`, `sesb`) as `key:value` pairs separated by `::`. **Constraint:** the assembled `isb` must not exceed **256 characters**. Exceeding this returns `400 BAD_REQUEST` with *"Issuer Subject length must be less than 256 characters"*. **Length calculation breakdown** (with `gcid`=26, `rcid`=26, `chid`≤100). Overhead = key chars + each key's trailing `:` + `::` separators between pairs. | Shape | Overhead | Fixed values | Remaining budget | |---|---|---|---| | Guest | 32 | gcid 26 + chid 100 = 126 | 98 | | Registered | 39 | gcid 26 + rcid 26 + chid 100 = 152 | 65 | | TSOB guest | 39 | gcid 26 + chid 100 = 126 | 91 - len(tsob) | | TSOB registered | 46 | gcid 26 + rcid 26 + chid 100 = 152 | 58 - len(tsob) | | Pwdless | 47 | gcid 26 + rcid 26 + chid 100 = 152 | 57 - len(login) | | SESB guest | 39 | gcid 26 + chid 100 = 126 | 91 - len(sesb) | | SESB registered | 46 | gcid 26 + rcid 26 + chid 100 = 152 | 58 - len(sesb) | | TAOB guest | 47 | gcid 26 + chid 100 = 126 | 83 - len(taob + agent) | | TAOB registered | 54 | gcid 26 + rcid 26 + chid 100 = 152 | 50 - len(taob + agent) | **Worst case (TAOB registered):** ``` 256 total - 54 overhead - 26 gcid - 26 rcid - 100 chid (allowed max) ---- 50 Then if taob = ta_ext_on_behalf_of: 50 - 19 = 31 Meaning only 31 characters remain for uido + upn + uidn + agent. ``` **Practical caps per variable sub-claim:** | Sub-claim | Description | Max length | |---|---|---| | `uido` | Identity origin | ~20 | | `upn` | Login ID / email | ~80 | | `uidn` | Display name (after `%3A` escaping) | ~60 | | `tsob` / `taob` | Trusted-system / trusted-agent hint | ~21 | | `agent` | Agent ID | ~32 | | `login` | Passwordless literal (e.g. `pwdless`) | short | | `sesb` | Session-bridge hint | short | | `chid` | Channel ID | 100 | **Notes:** - **Identity Origin Variance** — `uido` is a static IDP-configuration string (e.g. `ecom`, `google`, `Link_Brand_Production`). A longer origin reduces the budget available for user-supplied inputs. - **Double-Count Fallback** — if a shopper registers without a first and last name, `uidn` is generated from the email (prefix as first name, domain as last name), so the email is effectively counted **twice** (once as `upn`, once as `uidn`). Long emails are the most common cause of overflow. - Colons inside `uidn` are URL-encoded as `%3A`, which can further inflate its length. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.usid - The shopper\'s unique identifier, if known. If not provided, a new USID is generated. * @param options.body.grant_type - Grant Type * @param options.body.hint - Type of system used for Trusted System On Behalf of requests. * @param options.body.login_id - The ID used by the shopper for trusted system access. If set to `guest`, a token is returned for a guest user. * @param options.body.idp_origin - IDPs that work with SLAS. Use `ecom` when using B2C Commerce is the identity provider. * @param options.body.client_id - The SLAS public client ID for use with trusted-system requests. * @param options.body.channel_id - The channel (ECOM site) that the user is associated with. * @param options.body.email_id - The email address for the shopper that is used for trusted-system requests. If not provided, `login_id` is used instead. * @param options.body.dnt - This is an optional parameter to set `Do Not Track` for the session. SLAS is making this available, but will not be used by B2C Commerce until after the 24.4 release. Values are: * `false` * `true` If not added the `dnt` value will default to `false`. Note: The default value for `dnt` is set to `false` for SLAS token requests except for Trusted Agent token request. For Trusted Agent token requests the default value for `dnt` is `true`. * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type TokenResponse otherwise. */ getTrustedSystemAccessToken(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: getTrustedSystemAccessTokenBodyType; }>, rawResponse?: T): Promise; /** * This endpoint returns identity information about the authenticated user in the form of OpenID Connect claims. It requires a valid access token and returns information such as user ID, name, email, and other identity attributes based on the scopes granted during authentication. * * If you would like to get a raw Response object use the other getUserInfo function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.parameters.channel_id - Used when getting user information for a SFCC login. For an B2C Commerce customer, this is angalous to the site ID. Required when getting user information for an B2C Commerce customer. * @param options.parameters.idpValidate - When a user authenticates via an IDP, SLAS calls the IDP's `/userinfo` endpoint to retrieve user information. Since some IDPs don't reliably return user info, set `idpValidate=false` to skip this call and use the user information already stored in SLAS instead. Default: `true` * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * * @returns A promise of type string. */ getUserInfo(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; channel_id?: string; idpValidate?: boolean; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; }>): Promise; /** * This endpoint returns identity information about the authenticated user in the form of OpenID Connect claims. It requires a valid access token and returns information such as user ID, name, email, and other identity attributes based on the scopes granted during authentication. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.parameters.channel_id - Used when getting user information for a SFCC login. For an B2C Commerce customer, this is angalous to the site ID. Required when getting user information for an B2C Commerce customer. * @param options.parameters.idpValidate - When a user authenticates via an IDP, SLAS calls the IDP's `/userinfo` endpoint to retrieve user information. Since some IDPs don't reliably return user info, set `idpValidate=false` to skip this call and use the user information already stored in SLAS instead. Default: `true` * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type string otherwise. */ getUserInfo(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; channel_id?: string; idpValidate?: boolean; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; }>, rawResponse?: T): Promise; /** * This endpoint provides OpenID Connect discovery information in a standardized format. It allows clients to programmatically discover SLAS capabilities, including available endpoints, supported authentication flows, token signing algorithms, and other configuration details. This information helps clients integrate with the authentication service with minimal manual configuration. * * If you would like to get a raw Response object use the other getWellknownOpenidConfiguration function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * * @returns A promise of type string. */ getWellknownOpenidConfiguration(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; }>): Promise; /** * This endpoint provides OpenID Connect discovery information in a standardized format. It allows clients to programmatically discover SLAS capabilities, including available endpoints, supported authentication flows, token signing algorithms, and other configuration details. This information helps clients integrate with the authentication service with minimal manual configuration. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type string otherwise. */ getWellknownOpenidConfiguration(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; }>, rawResponse?: T): Promise; /** * A basic auth header with Base64-encoded `clientId:secret` is required in the Authorization header, as well as an access token or refresh token. Use `token_type_hint` to help identify the token. * * If you would like to get a raw Response object use the other introspectToken function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.token - Token to inspect or revoke. * @param options.body.token_type_hint - Token Type Hint * * @returns A promise of type TokenActionRequest. */ introspectToken(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: introspectTokenBodyType; }>): Promise; /** * A basic auth header with Base64-encoded `clientId:secret` is required in the Authorization header, as well as an access token or refresh token. Use `token_type_hint` to help identify the token. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.token - Token to inspect or revoke. * @param options.body.token_type_hint - Token Type Hint * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type TokenActionRequest otherwise. */ introspectToken(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: introspectTokenBodyType; }>, rawResponse?: T): Promise; /** * The shopper's access token and refresh token are revoked. If the shopper authenticated with a B2C Commerce (B2C Commerce) instance, the OCAPI JWT is also revoked. Call this endpoint for registered users that have logged in using SLAS. Do not use this endpoint for guest users. Required header: Authorization header bearer token of the Shopper access token to log out. Required parameters: `refresh token`, `channel_id`, and `client`. * * If you would like to get a raw Response object use the other logoutCustomer function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.parameters.client_id - The SLAS public client ID or SLAS private client ID for use with trusted-agent requests. When using a private client ID a PKCE code challenge is not required. * @param options.parameters.refresh_token - Refresh token that was given during the access token request. * @param options.parameters.channel_id - The `channel_id` parameter must be provided if the shopper authenticated using the `login` endpoint with B2C Commerce. * @param options.parameters.hint - `hint=all-sessions` logs out all sessions and invalidates all refresh tokens for a shopper with the same SLAS user ID. This only works within the same session type. Sessions created through different authentication methods (/authorize vs. Trusted System On Behalf) are treated as separate sessions. To invalidate tokens with different SLAS User IDs, you must make explicit logout calls with each token. A shopper authenticated via both /authorize and TSOB has two separate sessions. You will need two logout calls (one per token) to fully log them out. If this query parameter is not provided, the default behavior is to log out only the current session that matches the refresh token in the request. If an incorrect value is provided for the hint other than `all-sessions`, the request fails. * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * * @returns A promise of type TokenResponse. */ logoutCustomer(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; client_id: string; refresh_token: string; channel_id?: string; hint?: LogoutCustomerHintEnum; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; }>): Promise; /** * The shopper's access token and refresh token are revoked. If the shopper authenticated with a B2C Commerce (B2C Commerce) instance, the OCAPI JWT is also revoked. Call this endpoint for registered users that have logged in using SLAS. Do not use this endpoint for guest users. Required header: Authorization header bearer token of the Shopper access token to log out. Required parameters: `refresh token`, `channel_id`, and `client`. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.parameters.client_id - The SLAS public client ID or SLAS private client ID for use with trusted-agent requests. When using a private client ID a PKCE code challenge is not required. * @param options.parameters.refresh_token - Refresh token that was given during the access token request. * @param options.parameters.channel_id - The `channel_id` parameter must be provided if the shopper authenticated using the `login` endpoint with B2C Commerce. * @param options.parameters.hint - `hint=all-sessions` logs out all sessions and invalidates all refresh tokens for a shopper with the same SLAS user ID. This only works within the same session type. Sessions created through different authentication methods (/authorize vs. Trusted System On Behalf) are treated as separate sessions. To invalidate tokens with different SLAS User IDs, you must make explicit logout calls with each token. A shopper authenticated via both /authorize and TSOB has two separate sessions. You will need two logout calls (one per token) to fully log them out. If this query parameter is not provided, the default behavior is to log out only the current session that matches the refresh token in the request. If an incorrect value is provided for the hint other than `all-sessions`, the request fails. * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type TokenResponse otherwise. */ logoutCustomer(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; client_id: string; refresh_token: string; channel_id?: string; hint?: LogoutCustomerHintEnum; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; }>, rawResponse?: T): Promise; /** * Generates a one-time password (OTP) and delivers it to the shopper via the specified mode (email or callback). The OTP can then be used with the `/otp/verify` endpoint to verify the shopper. When `mode` is `email`, the `email` field is required. A shopper is limited to 6 email OTP requests per 10-minute window. When `mode` is `callback`, the `callback_uri` field is required and must match a registered callback URI for the client. * * If you would like to get a raw Response object use the other requestOtp function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/base-url.html#realm-id) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/base-url.html#instance-id). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.client_id - The ID of the OAuth client. * @param options.body.channel_id - The identifier of the site that a request is being made in the context of. Attributes might have site specific values, and some objects may only be assigned to specific sites * @param options.body.user_id - User ID for the shopper requesting the OTP. * @param options.body.mode - Password Action delivery modes * @param options.body.email - Required when `mode` is `email`. Must match a registered email for the shopper. * @param options.body.callback_uri - Required when `mode` is `callback`. Must match a registered callback URI for the client. The callback URI must be a `POST` endpoint. Wildcards are not allowed. * @param options.body.locale - The locale for the OTP delivery template. Defaults to `en-US` for email mode. * * @returns A promise of type void. */ requestOtp(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: requestOtpBodyType; }>): Promise; /** * Generates a one-time password (OTP) and delivers it to the shopper via the specified mode (email or callback). The OTP can then be used with the `/otp/verify` endpoint to verify the shopper. When `mode` is `email`, the `email` field is required. A shopper is limited to 6 email OTP requests per 10-minute window. When `mode` is `callback`, the `callback_uri` field is required and must match a registered callback URI for the client. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/base-url.html#realm-id) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/base-url.html#instance-id). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.client_id - The ID of the OAuth client. * @param options.body.channel_id - The identifier of the site that a request is being made in the context of. Attributes might have site specific values, and some objects may only be assigned to specific sites * @param options.body.user_id - User ID for the shopper requesting the OTP. * @param options.body.mode - Password Action delivery modes * @param options.body.email - Required when `mode` is `email`. Must match a registered email for the shopper. * @param options.body.callback_uri - Required when `mode` is `callback`. Must match a registered callback URI for the client. The callback URI must be a `POST` endpoint. Wildcards are not allowed. * @param options.body.locale - The locale for the OTP delivery template. Defaults to `en-US` for email mode. * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type void otherwise. */ requestOtp(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: requestOtpBodyType; }>, rawResponse?: T): Promise; /** * This endpoint allows a customer to set a new password using a valid password reset token. The customer must provide the token received from the password/reset endpoint along with the desired new password. * * If you would like to get a raw Response object use the other resetPassword function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.client_id - -| The public client ID. When using the `hint` query parameter either a public or private client ID can be used. * @param options.body.pwd_action_token - Password action token that was returned from the `/password/reset` endpoint. * @param options.body.code_verifier - PKCE code verifier. Created by the client. The `code_challenge` is created by SHA256 hashing the `code_verifier` and Base64 encoding the resulting hash. The `code_verifier` should be a high entropy cryptographically random string with a minimum of 43 characters and a maximum of 128 characters. * @param options.body.new_password - The new password to set for the shopper associated with the password action token. * @param options.body.channel_id - The channel that the request is for. For a B2C Commerce request, this is angalous to the site ID. * @param options.body.hint - Adding a `hint` query parameter with a value of `cross_device` will remove the need to have the code_verifier for password reset request. If the `hint` query parameter is used it must also have been used in the password action request. * @param options.body.user_id - User ID for logging in. This is the id that is used to log into SFCC. Required only when hint is provided. * * @returns A promise of type void. */ resetPassword(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: resetPasswordBodyType; }>): Promise; /** * This endpoint allows a customer to set a new password using a valid password reset token. The customer must provide the token received from the password/reset endpoint along with the desired new password. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.client_id - -| The public client ID. When using the `hint` query parameter either a public or private client ID can be used. * @param options.body.pwd_action_token - Password action token that was returned from the `/password/reset` endpoint. * @param options.body.code_verifier - PKCE code verifier. Created by the client. The `code_challenge` is created by SHA256 hashing the `code_verifier` and Base64 encoding the resulting hash. The `code_verifier` should be a high entropy cryptographically random string with a minimum of 43 characters and a maximum of 128 characters. * @param options.body.new_password - The new password to set for the shopper associated with the password action token. * @param options.body.channel_id - The channel that the request is for. For a B2C Commerce request, this is angalous to the site ID. * @param options.body.hint - Adding a `hint` query parameter with a value of `cross_device` will remove the need to have the code_verifier for password reset request. If the `hint` query parameter is used it must also have been used in the password action request. * @param options.body.user_id - User ID for logging in. This is the id that is used to log into SFCC. Required only when hint is provided. * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type void otherwise. */ resetPassword(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: resetPasswordBodyType; }>, rawResponse?: T): Promise; /** * A basic auth header with Base64-encoded `clientId:secret` is required in the Authorization header, and the refresh token to be revoked is required in the body. * * If you would like to get a raw Response object use the other revokeToken function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.token - Token to inspect or revoke. * @param options.body.token_type_hint - Token Type Hint * * @returns A promise of type TokenActionRequest. */ revokeToken(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: revokeTokenBodyType; }>): Promise; /** * A basic auth header with Base64-encoded `clientId:secret` is required in the Authorization header, and the refresh token to be revoked is required in the body. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.token - Token to inspect or revoke. * @param options.body.token_type_hint - Token Type Hint * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type TokenActionRequest otherwise. */ revokeToken(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: revokeTokenBodyType; }>, rawResponse?: T): Promise; /** * Starts the WebAuthn authentication process by generating credential request options. Returns the challenge and allowed credentials for the user to authenticate with. The SLAS client must have the `sfcc.pwdless_login` scope to access this endpoint. * * If you would like to get a raw Response object use the other startWebauthnAuthentication function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.tenant_id - The ID of the tenant. * @param options.body.client_id - The ID of the OAuth client. * @param options.body.channel_id - The ID of the channel. * @param options.body.user_id - The ID of the user. * * @returns A promise of type PublicKeyCredentialRequestOptions. */ startWebauthnAuthentication(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: startWebauthnAuthenticationBodyType; }>): Promise; /** * Starts the WebAuthn authentication process by generating credential request options. Returns the challenge and allowed credentials for the user to authenticate with. The SLAS client must have the `sfcc.pwdless_login` scope to access this endpoint. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.tenant_id - The ID of the tenant. * @param options.body.client_id - The ID of the OAuth client. * @param options.body.channel_id - The ID of the channel. * @param options.body.user_id - The ID of the user. * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type PublicKeyCredentialRequestOptions otherwise. */ startWebauthnAuthentication(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: startWebauthnAuthenticationBodyType; }>, rawResponse?: T): Promise; /** * Starts the WebAuthn registration process by generating credential creation options. Returns the challenge and other parameters needed by the authenticator to create a new credential. The SLAS client must have the `sfcc.pwdless_login` scope to access this endpoint. * * If you would like to get a raw Response object use the other startWebauthnUserRegistration function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.client_id - OAuth client identifier. Required if Authorization header is not provided. * @param options.body.pwd_action_token - Password action token (TOTP) received by the user. The token length is either 6 or 8 digits, configurable in SLAS Admin. * @param options.body.user_id - The ID of the user. * @param options.body.channel_id - The ID of the channel. * @param options.body.display_name - Display name for the passkey. * @param options.body.nick_name - Nickname for the credential. * * @returns A promise of type object. */ startWebauthnUserRegistration(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: startWebauthnUserRegistrationBodyType; }>): Promise; /** * Starts the WebAuthn registration process by generating credential creation options. Returns the challenge and other parameters needed by the authenticator to create a new credential. The SLAS client must have the `sfcc.pwdless_login` scope to access this endpoint. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/get-started.html#instance-types). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.client_id - OAuth client identifier. Required if Authorization header is not provided. * @param options.body.pwd_action_token - Password action token (TOTP) received by the user. The token length is either 6 or 8 digits, configurable in SLAS Admin. * @param options.body.user_id - The ID of the user. * @param options.body.channel_id - The ID of the channel. * @param options.body.display_name - Display name for the passkey. * @param options.body.nick_name - Nickname for the credential. * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type object otherwise. */ startWebauthnUserRegistration(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: startWebauthnUserRegistrationBodyType; }>, rawResponse?: T): Promise; /** * Verifies a one-time password (OTP) previously issued by the `/otp/request` endpoint. On success, the OTP token is consumed and cannot be reused. Each new call to `/otp/request` invalidates any previously issued OTP. * * If you would like to get a raw Response object use the other verifyOtp function. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/base-url.html#realm-id) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/base-url.html#instance-id). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.pwd_action_token - Password action token (TOTP) received by the user. The token length is either 6 or 8 digits, configurable in SLAS Admin. * @param options.body.client_id - The ID of the OAuth client. * @param options.body.channel_id - The identifier of the site that a request is being made in the context of. Attributes might have site specific values, and some objects may only be assigned to specific sites * @param options.body.user_id - The user ID of the shopper whose OTP is being verified. * * @returns A promise of type void. */ verifyOtp(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: verifyOtpBodyType; }>): Promise; /** * Verifies a one-time password (OTP) previously issued by the `/otp/request` endpoint. On success, the OTP token is consumed and cannot be reused. Each new call to `/otp/request` invalidates any previously issued OTP. * * @param options - An object containing the options for this method. * @param options.parameters - An object containing the parameters for this method. * @param options.parameters.organizationId - An identifier for the Salesforce Commerce Cloud organization the request is being made by. It consists of a prefix 'f_ecom_' followed by a 4-character [realm identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/base-url.html#realm-id) and a 3-character [instance type identifier](https://developer.salesforce.com/docs/commerce/commerce-api/guide/base-url.html#instance-id). * @param options.retrySettings - Retry options for the `node-retry` package * @param options.fetchOptions - Fetch options for the `make-fetch-happen` package * @param options.headers - An object literal of key value pairs of the headers to be sent with this request. * @param options.body - The data to send as the request body. * @param options.body.pwd_action_token - Password action token (TOTP) received by the user. The token length is either 6 or 8 digits, configurable in SLAS Admin. * @param options.body.client_id - The ID of the OAuth client. * @param options.body.channel_id - The identifier of the site that a request is being made in the context of. Attributes might have site specific values, and some objects may only be assigned to specific sites * @param options.body.user_id - The user ID of the shopper whose OTP is being verified. * @param rawResponse - Set to true to return entire Response object instead of DTO. * * @returns A promise of type Response if rawResponse is true, a promise of type void otherwise. */ verifyOtp(options?: RequireParametersUnlessAllAreOptional<{ parameters?: CompositeParameters<{ organizationId: string; } & QueryParameters, CommonParameters>; retrySettings?: OperationOptions; fetchOptions?: RequestInit; headers?: { [key: string]: string; }; body: verifyOtpBodyType; }>, rawResponse?: T): Promise; }