Private/Get-PASOAuthWebSession.ps1

function Get-PASOAuthWebSession {
    <#
    .SYNOPSIS
    Returns a WebSession configured for OAuth 2.0 Bearer token authentication

    .DESCRIPTION
    psPAS helper function.
    Creates a WebRequestSession with the CyberArk OAuth Authorization and X-CA-Authentication-Type headers set,
    adding any client certificate provided directly or resolved by thumbprint from the certificate store.

    .PARAMETER AccessToken
    The OAuth 2.0 access token. Any 'Bearer ' prefix is removed.

    .PARAMETER Certificate
    A client certificate to add to the WebSession.

    .PARAMETER CertificateThumbprint
    Thumbprint of a client certificate in Cert:\CurrentUser\My or Cert:\LocalMachine\My to add to the WebSession.

    .PARAMETER SkipCertificateCheck
    Skip SSL certificate validation.

    .EXAMPLE
    $psPASSession.WebSession = Get-PASOAuthWebSession -AccessToken $AccessToken
    #>

    [CmdletBinding()]
    [OutputType('Microsoft.PowerShell.Commands.WebRequestSession')]
    param(
        [parameter(
            Mandatory = $true
        )]
        [SecureString]$AccessToken,

        [parameter(
            Mandatory = $false
        )]
        [X509Certificate]$Certificate,

        [parameter(
            Mandatory = $false
        )]
        [string]$CertificateThumbprint,

        [parameter(
            Mandatory = $false
        )]
        [switch]$SkipCertificateCheck
    )

    process {

        if ($SkipCertificateCheck) {
            if (-not (Test-IsCoreCLR)) {
                Skip-CertificateCheck
            } else {
                $Script:SkipCertificateCheck = $true
            }
        }

        $WebSession = New-Object Microsoft.PowerShell.Commands.WebRequestSession

        if ($Certificate -or $CertificateThumbprint) {
            $WebSession.Certificates = New-Object System.Security.Cryptography.X509Certificates.X509CertificateCollection
        }

        if ($Certificate) {
            $WebSession.Certificates.Add($Certificate) | Out-Null
        }

        if ($CertificateThumbprint) {
            #Resolve certificate from the store and add to WebSession
            $ClientCertificate = Get-ChildItem -Path 'Cert:\CurrentUser\My', 'Cert:\LocalMachine\My' |
                Where-Object { $PSItem.Thumbprint -eq $CertificateThumbprint } | Select-Object -First 1

            if ($null -ne $ClientCertificate) {
                $WebSession.Certificates.Add($ClientCertificate) | Out-Null
            } else {
                throw "No certificate with thumbprint $CertificateThumbprint found in Cert:\CurrentUser\My or Cert:\LocalMachine\My"
            }
        }

        #Set required CyberArk OAuth headers
        $WebSession.Headers['Authorization'] = "Bearer $((ConvertTo-InsecureString -SecureString $AccessToken) -replace '^Bearer\s+', '')"
        $WebSession.Headers['X-CA-Authentication-Type'] = 'OAuth'

        $WebSession

    }

}