Courseiva
API Automation →mediumMultiple Choice

UiPath-ADPv1 API Automation Practice Question

A developer is building an API workflow that must call a protected endpoint. The API requires a Bearer token that expires every 60 minutes. The developer uses the HTTP Request activity in a UiPath Studio project and wants to avoid hardcoding credentials. They have already configured an Orchestrator asset of type Credential named 'ApiUser' that stores the client ID and secret. Which approach should the developer use to obtain and attach the token to each request?

⚠ Common exam trap

The trap here is assuming the HTTP Request activity can directly consume an Orchestrator credential asset for OAuth 2.0 without an explicit token call.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the Get Credential activity to retrieve the asset, then call the token endpoint with the HTTP Request activity, store the token in a variable, and add an Authorization header with value 'Bearer ' + token to subsequent requests.

The correct approach is to retrieve the credential asset securely, call the token endpoint to obtain a Bearer token, and then attach that token as an Authorization header on subsequent requests. This avoids hardcoding secrets and leverages Orchestrator's credential management. The token can be stored in a variable and refreshed when it expires, ensuring continued access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the Get Asset activity to retrieve the credential as a string, then pass it directly in the body of every API request as a password field.

    Why it's wrong here

    Get Asset returns a string but for a Credential asset it may not return the password; Get Credential is designed for credential assets. Passing credentials in the body of every request exposes secrets in logs and is not how Bearer tokens work. The API expects an Authorization header, not a password field, so authentication will fail.

  • ✗

    Store the token in an Orchestrator queue item and have each HTTP Request activity read the token from the queue using Get Transaction Item.

    Why it's wrong here

    Queues are for transactional work distribution, not for storing live authentication tokens. Token values are short-lived and sensitive; putting them in queue items risks exposure and adds unnecessary complexity. The HTTP Request activity cannot automatically read a token from a queue item, so the request would lack the Authorization header and be rejected.

  • ✗

    Configure the HTTP Request activity's Authentication property to use the Orchestrator credential asset directly, and select OAuth 2.0 as the authentication type.

    Why it's wrong here

    The HTTP Request activity does not have a built-in Authentication property that directly references an Orchestrator credential asset for OAuth 2.0 token acquisition. While some activities support simple authentication types, automatic token retrieval from a credential asset is not a native feature here. The developer must explicitly call the token endpoint and manage the header.

  • ✓

    Use the Get Credential activity to retrieve the asset, then call the token endpoint with the HTTP Request activity, store the token in a variable, and add an Authorization header with value 'Bearer ' + token to subsequent requests.

    Why this is correct

    This approach retrieves the secret securely from Orchestrator, obtains a token via the HTTP Request activity, and attaches it as a Bearer header. It avoids hardcoding and supports token refresh by re-running the token call when needed. The variable can be reused across requests within the same run, and the credential asset is protected by Orchestrator.

About these practice questions

This UiPath-ADPv1 question is part of Courseiva's 276-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official UiPath exam blueprint

This UiPath-ADPv1 practice question is part of Courseiva's free UiPath certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the UiPath-ADPv1 exam.