Appearance
Client Credentials Flow
The client credentials flow is for server-to-server communication where no user is involved. The application authenticates directly using its client ID and secret.
When to Use
- Background jobs that sync data
- Server-side integrations that don't act on behalf of a specific user
- Automated reporting or data pipelines
Flow Overview
Request a Token
bash
curl -X POST /oauth/token \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "grant_type=client_credentials" \
-d "client_id=YOUR_CLIENT_ID" \
-d "client_secret=YOUR_CLIENT_SECRET" \
-d "scope=projects:read invoices:read"Or using HTTP Basic authentication:
bash
curl -X POST /oauth/token \
-u "YOUR_CLIENT_ID:YOUR_CLIENT_SECRET" \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "grant_type=client_credentials" \
-d "scope=projects:read invoices:read"Response
json
{
"access_token": "eyJhbG...",
"token_type": "Bearer",
"expires_in": 900,
"scope": "projects:read invoices:read"
}WARNING
Client credentials tokens do not include a refresh token. Request a new token when the current one expires.
JavaScript Example
javascript
async function getToken() {
const response = await fetch('https://developer.knowify.com/oauth/token', {
method: 'POST',
headers: { 'Content-Type': 'application/x-www-form-urlencoded' },
body: new URLSearchParams({
grant_type: 'client_credentials',
client_id: process.env.CLIENT_ID,
client_secret: process.env.CLIENT_SECRET,
scope: 'projects:read',
}),
});
const data = await response.json();
return data.access_token;
}Security Notes
- Store client secrets securely (environment variables, secrets manager)
- Never expose client secrets in client-side code or version control
- Use the minimum required scopes