This page provides a sample setup for utilizing Temporary Authorization along with a pattern for refreshing the tokens. Since Temporary Authorization requires being logged into the realm you'll need to create this as a code page in your own realm to test.

URLRoot() & "db/" & AppId() & "?a=dbpage&pageid=16" // Open code page 16
& "&dbid=" & Dbid()  // Pass in the Table ID of the table to test with
& "&apptoken=" & [App Token]
<html lang="en">
    <link rel="stylesheet" href="">
    <script src = ''> </script>
        const headers = new Map; // All headers that utilize Temp Tokens will be stored/updated in this global variable

        function run(){

            const urlParams = new URLSearchParams(;
            const dbid = urlParams.get('dbid');
            const appToken = urlParams.get('apptoken');
            const realm = window.location.hostname.substring(0,window.location.hostname.indexOf("."));
            const dbids = [dbid]; // Temp Auth will be retrieved for all DBIDs in this array

            // call the authLoop function, passing in the realm, dbids, and apptoken

                statusStream(`These headers can now be used for API calls to ${dbid}:`);
                // statusStream(JSON.stringify(headers.get(dbid))); // This is a simplified (non-formatted) way to display the same info as below
                // The next three lines are broken out for easier to read formatting on the page itself
                statusStream(`{"QB-Realm-Hostname": "${headers.get(dbid)['QB-Realm-Hostname']}"`);
                statusStream(`"userAgent": "${headers.get(dbid)['userAgent']}"`);
                statusStream(`"Authorization": "${headers.get(dbid)['Authorization']}"}`);
                statusStream('<br><h1>Stick around to see the token automatically refresh in 15 seconds</h1><br>');

                // Run the rest of your functions here
                // Sample Query Call
                    url: ``,
                    method: 'POST',
                    headers: headers.get(dbid), // This is pulling the header generated with temp auth
                    dataType: "json",
                    contentType: "application/json; charset=utf-8",
                    data: JSON.stringify({"from":dbid,"where":"{3.GT.0}","options":{"top":1}}),
                    success: function (response) {
                        // console.log(JSON.stringify(response, null, 2));
            // Start the auth refresh timer


        function refreshTempAuth(realm, dbids, apptoken) {
            // Temp Auth tokens are only valid for 5 mins - This refreshes those tokens every 4 mins to prevent errors when the script runs longer than 5 mins
            setInterval(() => {
                statusStream(`<span style="color:green"><b>It's been 15 seconds, refreshing Temp Token now...</b></span>`)
                authLoop(realm, dbids, apptoken);

            }, 15000); // Currently set to refresh every 15 seconds || *** Recommended setting for a Production env is 240000 (4 mins) ***
        async function authLoop(realm, dbids, apptoken){
            // Loop through each dbid to get the temporary authentication
            for (let i = 0; i < dbids.length; i++) {
                await getTempAuth(realm,dbids[i],apptoken).then((header)=>{
                    headers.set(dbids[i], header); // Store the temp auth in the headers map
        function getTempAuth(realm, dbid, appToken) {
            return new Promise(function(resolve) {
                statusStream(`Making API call to <i>${dbid}</i>...`)
                    url: `${dbid}`,
                    method: 'GET',
                    headers: {
                        'QB-Realm-Hostname': realm,
                        'userAgent': 'QB APIGateway',
                        'QB-App-Token': appToken
                    xhrFields: {
                        withCredentials: true
                    success: function (data) {
                        statusStream(`<b>Temp Token</b>: ${data.temporaryAuthorization}`);
                        statusStream(`This temporary token has access to Table ID <b>${dbid}</b> for 5 minutes<br>`)
                        // return the header object, with temp token, for the specified dbid
                            'QB-Realm-Hostname': realm,
                            'userAgent': 'QB APIGateway',
                            'Authorization': `QB-TEMP-TOKEN ${data.temporaryAuthorization}`

        function statusStream(message) {
            // Add message to the on screen status stream
            document.getElementById('statusLog').insertAdjacentHTML("beforeend", `${message}<br>`);
        function rdr(num){
            if(num===1) {
                window.location.href = document.referrer; // Redirect to the previous page
                window.location.href = window.location.origin + window.location.pathname; // Redirect to the app home page
    <title>Get Temporary Tokens</title>
<body onload="run()">
<div class="text-center" id="form" >
    <h2>Get Temporary Token</h2>
    <div id="statusLog" style="font-size:20px"  class="text-center"></div> <!-- This is the element that the statusStream writes to -->
    <div id="nav" hidden>
        <h3>Where would you like to be redirected to?</h3>
        <a class="btn btn-primary" onclick="rdr(2)" role="button">Dashboard</a>
        <a class="btn btn-primary" onclick="rdr(1)" role="button">Previous Page</a>

These code samples are provided "AS IS" without any warranties of any kind and is not supported by Quickbase teams.
You are responsible for the security and maintenance of any third-party code inside of your application.
Any reliance on Quickbase functions, HTML, CSS or other document-object-model (DOM) elements should be considered unstable and may change at any time, without notice.

Builders should not reference or rely on common libraries hosted by Quickbase (such as jQuery or Angular) as these may change at any time.
Customers should reference their own hosted libraries or from 3rd-party resources that they can trust and maintain
Show fields from Show fields from Show fields from a related table
Report Name *
Reports and Charts Panel
Each table has a panel listing its reports and charts, organized in groups.
Please wait while your new report is saved...
Field label
Column heading override
What does auto mean?
Fields in:

Fields to Extract:

Name for the new table:
Items in the new table are called:

When you bring additional fields into a conversion, Quickbase often finds inconsistencies. For example, say you're converting your Companies column into its own table. One company, Acme Corporation, has offices in New York, Dallas and Portland. So, when you add the City column to the conversion, Quickbase finds three different locations for Acme. A single value in the column you're converting can only match one value in any additional field. Quickbase needs you to clean up the extra cities before it can create your new table. To do so, you have one of two choices:

  • If you want to create three separate Acme records (Acme-New York, Acme-Dallas and Acme-Portland) click the Conform link at the top of the column.
  • If the dissimilar entries are mistakes (say Acme only has one office in New York and the other locations are data-entry errors) go back into your table and correct the inconsistencies—in this case, changing all locations to New York. Then try the conversion again.

Read more about converting a column into a table.

We're glad you're interested in doing more with Quickbase!

Now we need to make you official before you share apps or manage your account.

Verifying your email lets you share Quickbase with others in your company.

Your work email
Your company