Authenticate via search token

This article explains how to employ Coveo search token authentication in an SAP Commerce Cloud project. Using this authentication method provides better security, as it doesn’t require exposing the API key in the front-end code.


Make sure your configuration meets the following criteria:

Back-end configuration

Step 1: Add an OCC extension

To use search token authentication, you must add a new API to the OCC extension of your project. Whereas you can do so by building a new extension from scratch, we recommend using the prebuilt extension published on Coveo GitHub:

  1. Go to your SAP project directory.

  2. Navigate to the hybris/bin/custom directory.

  3. Clone or download the extension repository. This would create a new directory named coveocc.

  4. In the project directory, open the hybris/config/localextensions.xml file and add the coveocc extension:

    <extension name='coveocc' />
  5. Save the file.

Step 2: Build and run the server

  1. From the root of your project directory, run the following command:

    ant clean all
  2. After the command execution, navigate to the hybris/bin/platform directory.

  3. Run the script:


Step 3: Specify credentials

The Coveo credentials should be set through the graphical interface of the Backoffice Administration Cockpit.

  1. In the Administration Cockpit, go to the WCMS → Website page.

  2. In the list of sites, double-click the required website.

  3. Switch to the Administration tab.

  4. Fill in the following fields:

Local testing

To test retrieving a search token, you can use a Swagger UI that’s available when you’re running the script. By default, your local server would use ports 9001 (http) and 9002 (https). The Swagger UI is available at https://localhost:9002/occ/v2/swagger-ui.html, where you can find and test the /coveo/token/ endpoint.

This endpoint returns a JSON object with the token property that contains the search token. Depending on the user type, the endpoint returns a JWT token for a logged-in user or an anonymous user.


Your implementation may use price groups to manage user-specific pricing. Price groups can be attached to a user group or directly to the user.

Either way, JWT tokens will contain all the price group IDs that are associated with a logged-in user.

See more about user groups in the SAP documentation.

Front-end configuration

Step 1: Add a new file

  1. Navigate to the root of your angular application (for example, src/app directory).

  2. Create a new service for token management, search-token-service/search-token.service.ts:

    import { CoreEngine } from '@coveo/atomic-angular'
    import { loadConfigurationActions } from '@coveo/headless'
    import { EventEmitter, Injectable, InjectionToken, Inject } from '@angular/core';
    import { AuthStorageService, EventService, LoginEvent, LogoutEvent } from '@spartacus/core';
    import {environment} from "../../environments/environment";
    export const SEARCH_HUB = new InjectionToken<string>('searchHub');
    export class SearchTokenService {
      public newTokenGenerated: EventEmitter<string> = new EventEmitter<string>();
      private TOKEN_PREFIX: string = `coveo-jwt`;
      private readonly searchHub: string
        private events: EventService,
        private authStorageService: AuthStorageService,
        @Inject(SEARCH_HUB) searchHub: string) {
        this.searchHub = searchHub;
          .subscribe( () => {
            removeAccessToken(this.TOKEN_PREFIX, this.searchHub);
          .subscribe(() => {
      getToken() {
        return getAccessToken({
          prefix: this.TOKEN_PREFIX,
          searchHub: this.searchHub,
          hybrisToken: this.authStorageService.getItem('access_token')})
      refreshToken() {
        return getAccessToken({
          prefix: this.TOKEN_PREFIX,
          searchHub: this.searchHub,
          refresh: true,
          hybrisToken: this.authStorageService.getItem('access_token')})
      reloadSearchEngineWithToken(engine: CoreEngine, token: string) { 1
        if (engine) {
          const {updateBasicConfiguration} = loadConfigurationActions(engine);
          const action = updateBasicConfiguration({accessToken: token})
      private async emitEvent() {
        this.newTokenGenerated.emit(await getAccessToken({ 2
          prefix: this.TOKEN_PREFIX,
          searchHub: this.searchHub,
          hybrisToken: this.authStorageService.getItem('access_token')
    function removeAccessToken(prefix: string, searchHub: string) {
      for (let i = 0; i < localStorage.length; i++) {
        const key = localStorage.key(i)
        if (key && key.startsWith(`${prefix}-${searchHub}`) && !key.startsWith(`${prefix}-${searchHub}-guest`)) {
    interface GetAccessTokenOptions {
      prefix: string;
      searchHub: string;
      refresh?: boolean;
      hybrisToken: string;
    async function getAccessToken(options: GetAccessTokenOptions) {
      const {prefix, searchHub, refresh = false, hybrisToken} = options;
      const usertype = hybrisToken ? 'user' : 'guest'; 3
      const cache = createTokenCache(prefix, usertype, searchHub);
      const cachedToken = cache.get();
      if (cachedToken && !refresh) return cachedToken;
      const token = await generateAccessToken(searchHub, hybrisToken);
      token && cache.set(token);
      return token;
    function createTokenCache(prefix: string, usertype: string, searchHub: string) { 4
      const key = `${prefix}-${searchHub}-${usertype}`; 5
      const get = () => localStorage.getItem(key);
      const set = (token: string) => localStorage.setItem(key, token);
      return { get, set };
    async function generateAccessToken(searchHub: string, hybrisToken: string | undefined) { 6
      const url = getCoveoAccessTokenUrl(searchHub);
      const headers: Record<string, string> = {};
      if (hybrisToken) {
        headers['Authorization'] = `Bearer ${hybrisToken}`;
      const requestOptions: RequestInit = {
        method: 'GET',
        headers: headers,
      try {
        const response = await fetch(url, requestOptions);
        const data = await response.json();
        return data.token;
      } catch (error) {
        console.error('Request failed:', error);
        return '';
    function getCoveoAccessTokenUrl(searchHub: string) {
      const base = environment.occBaseUrl;
      const baseSiteId = '<YOUR_SITE_ID>'; 7
      return `${base}occ/v2/${baseSiteId}/coveo/token/${searchHub}`;
1 reloadSearchEngineWithToken updates the engine configuration with the new JWT token when a user changes its authentication status.

Once a user logs in or logs out, the emitEvent method is called to emit a new token.

2 The service uses the emitEvent method to inform the app about the generation of a new token and retrieve it.
3 getAccessToken checks if checks if there’s a token in the localStorage. If not, it check whether it’s a logged-in user or an anonymous user and creats a cache token based on the user type. Finally, it calls generateAccessToken to create and retrieve a new token.
4 createTokenCache creates a cache object that exposes get and set methods to retrieve and store the token in the localStorage.
5 A separate cache entry is created if the searchHub value wasn’t in the localStorage.
6 generateAccessToken calls the getCoveoAccessTokenUrl function which returns the URL of OCC extension that retrieves the token.
7 Saves the ID of your site into a baseSiteId variable. The site ID is the one that you configured in the Backoffice Administration Cockpit.

Step 2: Update app.component.ts

Update the src/app/app.component.ts file to use the getAccessToken method:

import { AfterViewInit, Component, ViewChild } from '@angular/core';
import { AtomicSearchInterface, loadFieldActions } from '@coveo/atomic-angular';
import {SearchTokenService, SEARCH_HUB} from "./search-token-service/search-token.service";

  selector: 'app-root',
  templateUrl: './app.component.html',
  styleUrls: ['./app.component.scss'],
  providers: [
    {provide: SEARCH_HUB, useValue: "Search" },

export class AppComponent implements AfterViewInit {
  @ViewChild('searchinterface') searchInterface?: AtomicSearchInterface;
  title = 'powertoolsstore';
  searchHub = '<MY_SEARCH_HUB>';
    private searchTokenService: SearchTokenService
  ) {}

  async ngAfterViewInit() {

    const accessToken = await this.searchTokenService.getToken();

    if (!accessToken) {

    this.searchTokenService.newTokenGenerated.subscribe((value) => { 1
      const engine = this?.searchInterface?.engine;
      if (engine) {
        this.searchTokenService.reloadSearchEngineWithToken(engine, value);
      } else {

  private initalizeSearchInterface(accessToken: string) {
        organizationId: '<YOUR_ORG_ID>', 2
        search: { searchHub: this.searchHub },
        renewAccessToken: () => this.searchTokenService.refreshToken()
      .then(() => {
        const engine = this?.searchInterface?.engine;

        if (engine) {

          // ... 3

1 Subscribe to the newTokenGenerated event to reload the engine with the new JWT token.
2 Pass the following parameters:
  • ID of your Coveo organization

  • Search hub

  • Access token

  • renewAccessToken method that renews the token if it’s expired.

    See initialize.

3 You can further specify the engine configuration before executing the first search. See atomic-search-interface properties.

From now on, your storefront will use the search token to authenticate the search requests.