Forum Discussion
How to use Power BI Rest API without GUI authentication (redirect uri)
- 10 years ago
You can use the user name and password flow that AAD supports. This 3rd party client library has an example: https://github.com/Vtek/PowerBI.Api.Client
Below is the code for getting AccessToken by giving User credential, client Id (without AccessCode & Azure-Login UI).
using Newtonsoft.Json;
using System.IO;
using System.Text;
private async void SetAccessToken()
{
List<KeyValuePair<string, string>> vals = new List<KeyValuePair<string, string>>();
vals.Add(new KeyValuePair<string, string>("grant_type", "password"));
vals.Add(new KeyValuePair<string, string>("scope", "openid"));
vals.Add(new KeyValuePair<string, string>("resource", "https://analysis.windows.net/powerbi/api"));
vals.Add(new KeyValuePair<string, string>("client_id", ""));
vals.Add(new KeyValuePair<string, string>("client_secret", ""));
vals.Add(new KeyValuePair<string, string>("username", ""));
vals.Add(new KeyValuePair<string, string>("password", ""));
string TenantId = "";
string url = string.Format("https://login.windows.net/{0}/oauth2/token", TenantId);
HttpClient hc = new HttpClient();
HttpContent content = new FormUrlEncodedContent(vals);
HttpResponseMessage hrm = hc.PostAsync(url, content).Result;
string responseData = "";
if (hrm.IsSuccessStatusCode)
{
Stream data = await hrm.Content.ReadAsStreamAsync();
using (StreamReader reader = new StreamReader(data, Encoding.UTF8))
{
responseData = reader.ReadToEnd();
}
}
Token = JsonConvert.DeserializeObject<AccessToken>(responseData);
}
public class AccessToken
{
public string token_type;
public string scope { get; set; }
public string expires_in { get; set; }
public string expires_on { get; set; }
public string not_before { get; set; }
public string resource { get; set; }
public string access_token { get; set; }
public string refresh_token { get; set; }
public string id_token { get; set; }
}
- spappuru9 years agoNew Member
After executing the above code by replacing the values for ClientID,ClientSecret and TenantId, I am seeing the below error :
Message: The remote server returned an error: (400) Bad Request.
Status: ProtocolError.
I have also tried using the authority uri as https://login.microsoftonline.com/<TenantID>/oauth2/token but still the same error.
I really appreciate your response why I am seeing this bad request error.
- VishvaPowerBI10 years agoRegular Visitor
Hi,
I am bit confused as to where I can call this code for test. I am new to C# and it may be the reason for confusion. However I went thru some sample codes in sample application embed-a-tile-into-an-app (Github -dvana/PowerBI-CSharp) etc.. Any chance you could explain some dtails on how to use this code etc..
Regards,
Vish.
- Phil_Seamark10 years ago
Microsoft Employee
Hi there,
What do you use for the Username/Password for your solution.
We use SSO at our company so not sure what account I can use.
- heitzmanjared10 years agoFrequent Visitor
I currently use my personal credentials. We're planning a change soon. What sucks is that PowerBI doesn't really allow multiple users to build reports off an API dataset. Our plan is to get a shared Service Account, pay for a license for the service account, and keep the password private to our group.
- Phil_Seamark10 years ago
Microsoft Employee
So in my case, when I log into Power BI using our company SSO, I use the my internal company AD network username and password.
Are you saying these should work ok?
Oh and I take it your code is designed to work with a Web app? I'm trying to use and SSIS script task to push rows up to a Dataset\table.
- tarik9 years agoRegular Visitor
Hi there,
I'm using the same flow as you mentioned here but I'm always getting error at that part.If I use client credentials such as client_id then I get one token without any user consent dialog . (As long as I develop native java application I cant open a browser to pop it up.) Unfortunately I cant use this token to make a rest api call because I always get 403 forbidden. I understand that authentication for rest api calls should be user specific for Power Bi. So I use this example same as in the adal4f implementation and also with the post man rest tool. I encounter same error in both as you see in the pictures.
{ "error": "invalid_grant", "error_description": "AADSTS65001: The user or administrator has not consented to use the application with ID 'ef193d6d-5585-4286-bc7f-31eadd94446c'. Send an interactive authorization request for this user and resource.\r\nTrace ID: bd8c1e80-4965-4d85-b607-700505157055\r\nCorrelation ID: 9189059d-abea-4f30-8de1-321f25010dbd\r\nTimestamp: 2016-10-26 09:10:34Z", "error_codes": [ 65001 ], "timestamp": "2016-10-26 09:10:34Z", "trace_id": "bd8c1e80-4965-4d85-b607-700505157055", "correlation_id": "9189059d-abea-4f30-8de1-321f25010dbd" }private static void getPasswordCredentinal() throws IOException { HttpPost signIn = new HttpPost("https://login.windows.net/{mytenant}/oauth2/token"); List<NameValuePair> nvps = new ArrayList<>(); nvps.add(new BasicNameValuePair("grant_type","password")); nvps.add(new BasicNameValuePair("client_id","myId")); nvps.add(new BasicNameValuePair("resource","https://analysis.windows.net/powerbi/api")); nvps.add(new BasicNameValuePair("username","myuser")); nvps.add(new BasicNameValuePair("password","mypass")); nvps.add(new BasicNameValuePair("scope","openid")); //optinal signIn.setEntity(new UrlEncodedFormEntity(nvps)); CloseableHttpClient client = HttpClients.custom().build(); HttpResponse response = client.execute(signIn); System.out.println(response.getStatusLine().toString()+" "+response.getStatusLine().getReasonPhrase()+" "+response.getStatusLine().toString()); String s = EntityUtils.toString(response.getEntity()); JSONObject jsonObject=new JSONObject(s); accessToken = (String) jsonObject.opt("access_token"); System.out.println(" json object >"+jsonObject); }Both produce the same result.
"error_description": "AADSTS65001: The user or administrator has not consented to use the application with ID 'ef193d6d-5585-4286-bc7f-31eadd94446c'. Send an interactive authorization request for this user and resource
So is there anyting I'm missing? Or is there any way to bypass this consent process programmatically?
Thanks for your help - spappuru9 years agoNew Member
Can you please clarify what is the TenantId in the above code represents?
- tarik9 years agoRegular Visitor
https://login.windows.net/common/oauth2its actually "common" in my code. By ethier it can be domain according to azure active directory. Both works. I work as above.
- jstearnes8 years ago
Advocate I
That's very useful. However, when registering the application, what values did you use for the redirect URL? It appears to be a mandatory field but in this case, it is not being used
- skaratela8 years agoFrequent VisitorHi!
The redirect url is needed when creating the AAD app and not the post request... Unless it's changed recently.
Shaheen
- jstearnes8 years ago
Advocate I
Hi vijaybkodare I have tried this using Postman and I'm getting the following error:
{
"error": "invalid_grant",
"error_description": "AADSTS65001: The user or administrator has not consented to use the application with ID '3cc9615b-ed4c-436b-82a5-fb701c7e240d' named 'Launch BI'. Send an interactive authorization request for this user and resource.\r\nTrace ID: 46533754-26e3-43d9-9bea-2206d7ab3100\r\nCorrelation ID: c9e76852-19f3-4173-9866-5f914509fb7b\r\nTimestamp: 2018-01-16 17:31:30Z",
"error_codes": [
65001
],
"timestamp": "2018-01-16 17:31:30Z",
"trace_id": "46533754-26e3-43d9-9bea-2206d7ab3100",
"correlation_id": "c9e76852-19f3-4173-9866-5f914509fb7b"
}- jstearnes8 years ago
Advocate I
I just found the problem, the grant type needs to be "client_credentials" not "password"
- jstearnes8 years ago
Advocate I
I just realised that using the "client_credentials" grant type may not be suitable as the username and password parameters are not used. I switched back to using the "password" grant type but I also had to login to my Azure AD -> Registered Apps -> <App Name> -> All Settings -> Required Permissions and then click the "Grant Permissions" button