Skip to content

Client Credentials Flow ​

The client credentials flow is for server-to-server communication where no user is involved. The application authenticates directly using its client ID and secret.

When to Use ​

  • Background jobs that sync data
  • Server-side integrations that don't act on behalf of a specific user
  • Automated reporting or data pipelines

Flow Overview ​

Request a Token ​

bash
curl -X POST /oauth/token \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "grant_type=client_credentials" \
  -d "client_id=YOUR_CLIENT_ID" \
  -d "client_secret=YOUR_CLIENT_SECRET" \
  -d "scope=projects:read invoices:read"

Or using HTTP Basic authentication:

bash
curl -X POST /oauth/token \
  -u "YOUR_CLIENT_ID:YOUR_CLIENT_SECRET" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "grant_type=client_credentials" \
  -d "scope=projects:read invoices:read"

Response ​

json
{
  "access_token": "eyJhbG...",
  "token_type": "Bearer",
  "expires_in": 900,
  "scope": "projects:read invoices:read"
}

WARNING

Client credentials tokens do not include a refresh token. Request a new token when the current one expires.

JavaScript Example ​

javascript
async function getToken() {
  const response = await fetch('https://developer.knowify.com/oauth/token', {
    method: 'POST',
    headers: { 'Content-Type': 'application/x-www-form-urlencoded' },
    body: new URLSearchParams({
      grant_type: 'client_credentials',
      client_id: process.env.CLIENT_ID,
      client_secret: process.env.CLIENT_SECRET,
      scope: 'projects:read',
    }),
  });
  const data = await response.json();
  return data.access_token;
}

Security Notes ​

  • Store client secrets securely (environment variables, secrets manager)
  • Never expose client secrets in client-side code or version control
  • Use the minimum required scopes