Dart
Dart
Okta Client Credentials FLow
See more Okta OAuth/OIDC Examples
The Client Credentials flow is recommended for use in machine-to-machine authentication. Your application will need to securely store its Client ID and Secret and pass those to Okta in exchange for an access token. At a high-level, the flow only has two steps:- Your application passes its client credentials to your Okta authorization server.
- If the credentials are accurate, Okta responds with an access token.
Note: This example uses "customScope". You'll replace it with whatever scope(s) you've defined for your app. Scopes are defined in your Authorization Server. See Okta Authorization Server / Scopes
Chilkat Dart Downloads
import 'package:chilkat/chilkat.dart';
void main() {
// This example assumes the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
final http = CkHttp();
// Implements the following CURL command:
// curl --request POST \
// --url https://{yourOktaDomain}/oauth2/default/v1/token \
// --header 'accept: application/json' \
// --user "client_id:client_secret" \
// --header 'cache-control: no-cache' \
// --header 'content-type: application/x-www-form-urlencoded' \
// --data 'grant_type=client_credentials&scope=customScope'
http.login = 'client_id';
http.password = 'client_secret';
final req = CkHttpRequest();
req.httpVerb = 'POST';
req.path = '/oauth2/default/v1/token';
req.contentType = 'application/x-www-form-urlencoded';
req.addParam('grant_type', 'client_credentials');
req.addParam('scope', 'customScope');
req.addHeader('accept', 'application/json');
final resp = CkHttpResponse();
try {
http.httpReq('https://{yourOktaDomain}/oauth2/default/v1/token', req, resp);
} on ChilkatException catch (e) {
print(e.lastErrorText);
return;
}
final sbResponseBody = CkStringBuilder();
resp.getBodySb(sbResponseBody);
final jResp = CkJsonObject();
jResp.loadSb(sbResponseBody);
jResp.emitCompact = false;
print('Response Body:');
print(jResp.emit());
final respStatusCode = resp.statusCode;
print('Response Status Code = $respStatusCode');
if (respStatusCode >= 400) {
print('Response Header:');
print(resp.header);
print('Failed.');
return;
}
// Sample JSON response:
// (Sample code for parsing the JSON response is shown below)
// {
// "access_token": "eyJraWQiO ... B2CnCLj7GRUW3mQ",
// "token_type": "Bearer",
// "expires_in": 3600,
// "scope": "customScope"
// }
// Sample code for parsing the JSON response...
// Use the following online tool to generate parsing code from sample JSON:
// Generate Parsing Code from JSON
final accessToken = jResp.stringOf('access_token');
final tokenType = jResp.stringOf('token_type');
final expiresIn = jResp.intOf('expires_in');
final scope = jResp.stringOf('scope');
}