Java
Java
Okta Client Credentials FLow
See more Okta OAuth/OIDC Examples
The Client Credentials flow is recommended for use in machine-to-machine authentication. Your application will need to securely store its Client ID and Secret and pass those to Okta in exchange for an access token. At a high-level, the flow only has two steps:- Your application passes its client credentials to your Okta authorization server.
- If the credentials are accurate, Okta responds with an access token.
Note: This example uses "customScope". You'll replace it with whatever scope(s) you've defined for your app. Scopes are defined in your Authorization Server. See Okta Authorization Server / Scopes
Chilkat Java Downloads
import com.chilkatsoft.*;
public class ChilkatExample {
static {
try {
System.loadLibrary("chilkat");
} catch (UnsatisfiedLinkError e) {
System.err.println("Native code library failed to load.\n" + e);
System.exit(1);
}
}
public static void main(String argv[])
{
boolean success = false;
// This example assumes the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
CkHttp http = new CkHttp();
// Implements the following CURL command:
// curl --request POST \
// --url https://{yourOktaDomain}/oauth2/default/v1/token \
// --header 'accept: application/json' \
// --user "client_id:client_secret" \
// --header 'cache-control: no-cache' \
// --header 'content-type: application/x-www-form-urlencoded' \
// --data 'grant_type=client_credentials&scope=customScope'
http.put_Login("client_id");
http.put_Password("client_secret");
CkHttpRequest req = new CkHttpRequest();
req.put_HttpVerb("POST");
req.put_Path("/oauth2/default/v1/token");
req.put_ContentType("application/x-www-form-urlencoded");
req.AddParam("grant_type","client_credentials");
req.AddParam("scope","customScope");
req.AddHeader("accept","application/json");
CkHttpResponse resp = new CkHttpResponse();
success = http.HttpReq("https://{yourOktaDomain}/oauth2/default/v1/token",req,resp);
if (success == false) {
System.out.println(http.lastErrorText());
return;
}
CkStringBuilder sbResponseBody = new CkStringBuilder();
resp.GetBodySb(sbResponseBody);
CkJsonObject jResp = new CkJsonObject();
jResp.LoadSb(sbResponseBody);
jResp.put_EmitCompact(false);
System.out.println("Response Body:");
System.out.println(jResp.emit());
int respStatusCode = resp.get_StatusCode();
System.out.println("Response Status Code = " + respStatusCode);
if (respStatusCode >= 400) {
System.out.println("Response Header:");
System.out.println(resp.header());
System.out.println("Failed.");
return;
}
// Sample JSON response:
// (Sample code for parsing the JSON response is shown below)
// {
// "access_token": "eyJraWQiO ... B2CnCLj7GRUW3mQ",
// "token_type": "Bearer",
// "expires_in": 3600,
// "scope": "customScope"
// }
// Sample code for parsing the JSON response...
// Use the following online tool to generate parsing code from sample JSON:
// Generate Parsing Code from JSON
String access_token = jResp.stringOf("access_token");
String token_type = jResp.stringOf("token_type");
int expires_in = jResp.IntOf("expires_in");
String scope = jResp.stringOf("scope");
}
}