Skip to main content
Developer Communities Admin
Community Manager
September 15, 2026

We understand that different environments have different oAuth Token endpoints.

  • September 15, 2026
  • 9 replies
  • 0 views

Originally posted by Hong Zhao on February 25, 2026 at 8:37 PM.

 

We understand that different environments have different oAuth Token endpoints.

Dayforce environments may include: Production, Touch, Config, Test, Stage, Train etc.

 

for example:

stage web: "https://stage.dayforcehcm.com" :

oAuth Token endpoints = "https://dfidtst.np.dayforcehcm.com/connect/token";

 

config web: "https://config.dayforcehcm.com" :

oAuth Token endpoints = "https://dfidconfig.np.dayforcehcm.com/connect/token";

 

Is there a best practice for a pattern or manifest of all possible auth URLs?

 

If we have a presales environment - https://apjdemo.dayforcehcm.com, how can we find the OAuth Token Url for this environment?

 

Thanks,

Hong

 

    9 replies

    Developer Communities Admin
    Community Manager
    September 15, 2026

    Originally replied by Frank Ruffolo on Mar 10, 2026, 2:14 PM.

     

    Hey @Hong Zhao​  what's the user story here, because all integrations would eventually go to production and those URLs are explained on the DDN. But what would be the reason (I think I can guess) to be able to authenticate on these ancillary environments outside the ones listed on the DDN?

    Developer Communities Admin
    Community Manager
    September 15, 2026

    Originally replied by Frank Ruffolo on Mar 4, 2026, 10:28 AM.

     

    Hey @Hong Zhao​  let me see what I can find out.

    Developer Communities Admin
    Community Manager
    September 15, 2026

    Originally replied by Frank Ruffolo on Mar 11, 2026, 8:46 AM.

     

    Hi @Hong Zhao​ my question was more geared towards why would you need to auth to those other environments beyond the ones listed here <link stripped through migration>.

    Developer Communities Admin
    Community Manager
    September 15, 2026

    Originally replied by Hong Zhao on Mar 10, 2026, 5:43 PM.

     

    @Frank Ruffolo​ We're working on the TestAssure automation and need to pull Dayforce WFM data like timesheets and schedules. To do that, we’ll need both Web and API login access—specifically, we need to hit the OAuth token endpoints to authenticate our API credentials.

    Developer Communities Admin
    Community Manager
    September 15, 2026

    Originally replied by Hong Zhao on Mar 11, 2026, 10:23 AM.

     

    @Frank Ruffolo​ We received 2 new environments with their credentials - https://apjdemo.dayforcehcm.com and http://predemo.dayforce.hcm.com, How do we know their identity server endpoint is https://dfidconfig.np.dayforcehcm.com/connect/token or https://dfidtst.np.dayforcehcm.com/connect/token?

    Developer Communities Admin
    Community Manager
    September 15, 2026

    Originally replied by Frank Ruffolo on Mar 11, 2026, 11:25 AM.

     

    @Hong Zhao​ it's  https://dfidprdemo.np.dayforcehcm.com/ but why can't you use your Stage or Test to test/auth the integration?

    Developer Communities Admin
    Community Manager
    September 15, 2026

    Originally replied by Hong Zhao on Mar 11, 2026, 11:48 AM.

     

    @Frank Ruffolo​ Yes, we can try stage or test to test auth. Thanks!

    Developer Communities Admin
    Community Manager
    September 15, 2026

    Originally replied by Hong Zhao on Mar 13, 2026, 11:13 AM.

     

    @Frank Ruffolo​ We tested with https://dfidprdemo.np.dayforcehcm.com/connect/token, it gave us this error - {

      "error": "invalid_request",

      "error_description": "Unable to authenticate the user"

    }

    and we have to try with https://dfidconfig.np.dayforcehcm.com/connect/token, it is working.

     

    Developer Communities Admin
    Community Manager
    September 15, 2026

    Originally replied by Hong Zhao on Mar 13, 2026, 11:34 AM.

     

    An authentication token can be retrieved with an API call to Dayforce Identity servers.

    The call is a POST call on the following URLs:

    Production: https://dfid.dayforcehcm.com/connect/token

    Touch: https://dfid.dayforcehcm.com/connect/token

    Config: https://dfidconfig.np.dayforcehcm.com/connect/token

    Test: https://dfidtst.np.dayforcehcm.com/connect/token

    Stage: https://dfidtst.np.dayforcehcm.com/connect/token

    Train: https://dfidconfig.np.dayforcehcm.com/connect/token

     

    Given a Dayforce instance like https://apjdemo.dayforcehcm.com/ or https://predemo.dayforcehcm.com/, how do we know which URL we should use to do the authentication?