Sample code for 30+ languages & platforms
React Native

Okta Client Credentials FLow

See more Okta OAuth/OIDC Examples

The Client Credentials flow is recommended for use in machine-to-machine authentication. Your application will need to securely store its Client ID and Secret and pass those to Okta in exchange for an access token. At a high-level, the flow only has two steps:
  • Your application passes its client credentials to your Okta authorization server.
  • If the credentials are accurate, Okta responds with an access token.

Note: This example uses "customScope". You'll replace it with whatever scope(s) you've defined for your app. Scopes are defined in your Authorization Server. See Okta Authorization Server / Scopes

Chilkat React Native Downloads

React Native
import { Http, HttpRequest, HttpResponse, JsonObject, StringBuilder } from '@chilkat/react-native'

async function chilkatExample() {
  // This example assumes the Chilkat API to have been previously unlocked.
  // See Global Unlock Sample for sample code.

  const http = new Http();

  // Implements the following CURL command:

  // curl --request POST \
  //   --url https://{yourOktaDomain}/oauth2/default/v1/token \
  //   --header 'accept: application/json' \
  //   --user "client_id:client_secret" \
  //   --header 'cache-control: no-cache' \
  //   --header 'content-type: application/x-www-form-urlencoded' \
  //   --data 'grant_type=client_credentials&scope=customScope'

  http.login = 'client_id';
  http.password = 'client_secret';

  const req = new HttpRequest();
  req.httpVerb = 'POST';
  req.path = '/oauth2/default/v1/token';
  req.contentType = 'application/x-www-form-urlencoded';
  req.addParam('grant_type', 'client_credentials');
  req.addParam('scope', 'customScope');

  req.addHeader('accept', 'application/json');

  const resp = new HttpResponse();
  try {
    await http.httpReqAsync('https://{yourOktaDomain}/oauth2/default/v1/token', req, resp);
  } catch {
    console.log(http.lastErrorText);
    return;
  }

  const sbResponseBody = new StringBuilder();
  resp.getBodySb(sbResponseBody);
  const jResp = new JsonObject();
  jResp.loadSb(sbResponseBody);
  jResp.emitCompact = false;

  console.log('Response Body:');
  console.log(jResp.emit());

  const respStatusCode = resp.statusCode;
  console.log(`Response Status Code = ${respStatusCode}`);
  if (respStatusCode >= 400) {
    console.log('Response Header:');
    console.log(resp.header);
    console.log('Failed.');
    return;
  }

  // Sample JSON response:
  // (Sample code for parsing the JSON response is shown below)

  // {
  //   "access_token": "eyJraWQiO ... B2CnCLj7GRUW3mQ",
  //   "token_type": "Bearer",
  //   "expires_in": 3600,
  //   "scope": "customScope"
  // }

  // Sample code for parsing the JSON response...
  // Use the following online tool to generate parsing code from sample JSON:
  // Generate Parsing Code from JSON

  const accessToken = jResp.stringOf('access_token');
  const tokenType = jResp.stringOf('token_type');
  const expiresIn = jResp.intOf('expires_in');
  const scope = jResp.stringOf('scope');
}