Sample code for 30+ languages & platforms
Rust

Okta Client Credentials FLow

See more Okta OAuth/OIDC Examples

The Client Credentials flow is recommended for use in machine-to-machine authentication. Your application will need to securely store its Client ID and Secret and pass those to Okta in exchange for an access token. At a high-level, the flow only has two steps:
  • Your application passes its client credentials to your Okta authorization server.
  • If the credentials are accurate, Okta responds with an access token.

Note: This example uses "customScope". You'll replace it with whatever scope(s) you've defined for your app. Scopes are defined in your Authorization Server. See Okta Authorization Server / Scopes

Chilkat Rust Downloads

Rust

// This example assumes the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

let http = chilkat::Http::new();

// Implements the following CURL command:

// curl --request POST \
//   --url https://{yourOktaDomain}/oauth2/default/v1/token \
//   --header 'accept: application/json' \
//   --user "client_id:client_secret" \
//   --header 'cache-control: no-cache' \
//   --header 'content-type: application/x-www-form-urlencoded' \
//   --data 'grant_type=client_credentials&scope=customScope'

http.set_login("client_id");
http.set_password("client_secret");

let req = chilkat::HttpRequest::new();
req.set_http_verb("POST");
req.set_path("/oauth2/default/v1/token");
req.set_content_type("application/x-www-form-urlencoded");
req.add_param("grant_type", "client_credentials");
req.add_param("scope", "customScope");

req.add_header("accept", "application/json");

let resp = chilkat::HttpResponse::new();
if http.http_req("https://{yourOktaDomain}/oauth2/default/v1/token", &req, &resp).is_err() {
    println!("{}", http.last_error_text());
    return;
}

let sb_response_body = chilkat::StringBuilder::new();
let _ = resp.get_body_sb(&sb_response_body);
let j_resp = chilkat::JsonObject::new();
let _ = j_resp.load_sb(&sb_response_body);
j_resp.set_emit_compact(false);

println!("Response Body:");
println!("{}", j_resp.emit().unwrap_or_default());

let resp_status_code = resp.status_code();
println!("Response Status Code = {}", resp_status_code);
if resp_status_code >= 400 {
    println!("Response Header:");
    println!("{}", resp.header());
    println!("Failed.");
    return;
}

// Sample JSON response:
// (Sample code for parsing the JSON response is shown below)

// {
//   "access_token": "eyJraWQiO ... B2CnCLj7GRUW3mQ",
//   "token_type": "Bearer",
//   "expires_in": 3600,
//   "scope": "customScope"
// }

// Sample code for parsing the JSON response...
// Use the following online tool to generate parsing code from sample JSON:
// Generate Parsing Code from JSON

let access_token = j_resp.string_of("access_token").unwrap_or_default();
let token_type = j_resp.string_of("token_type").unwrap_or_default();
let expires_in = j_resp.int_of("expires_in");
let scope = j_resp.string_of("scope").unwrap_or_default();