Xbase++
Xbase++
Okta Client Credentials FLow
See more Okta OAuth/OIDC Examples
The Client Credentials flow is recommended for use in machine-to-machine authentication. Your application will need to securely store its Client ID and Secret and pass those to Okta in exchange for an access token. At a high-level, the flow only has two steps:- Your application passes its client credentials to your Okta authorization server.
- If the credentials are accurate, Okta responds with an access token.
Note: This example uses "customScope". You'll replace it with whatever scope(s) you've defined for your app. Scopes are defined in your Authorization Server. See Okta Authorization Server / Scopes
Chilkat Xbase++ Downloads
LOCAL nSuccess
LOCAL oHttp
LOCAL oReq
LOCAL oResp
LOCAL oSbResponseBody
LOCAL oJResp
LOCAL nRespStatusCode
LOCAL cAccess_token
LOCAL cToken_type
LOCAL nExpires_in
LOCAL cScope
nSuccess := 0
// This example assumes the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
oHttp := CreateObject("Chilkat.Http")
// Implements the following CURL command:
// curl --request POST \
// --url https://{yourOktaDomain}/oauth2/default/v1/token \
// --header 'accept: application/json' \
// --user "client_id:client_secret" \
// --header 'cache-control: no-cache' \
// --header 'content-type: application/x-www-form-urlencoded' \
// --data 'grant_type=client_credentials&scope=customScope'
oHttp:Login := "client_id"
oHttp:Password := "client_secret"
oReq := CreateObject("Chilkat.HttpRequest")
oReq:HttpVerb := "POST"
oReq:Path := "/oauth2/default/v1/token"
oReq:ContentType := "application/x-www-form-urlencoded"
oReq:AddParam("grant_type", "client_credentials")
oReq:AddParam("scope", "customScope")
oReq:AddHeader("accept", "application/json")
oResp := CreateObject("Chilkat.HttpResponse")
nSuccess := oHttp:HttpReq("https://{yourOktaDomain}/oauth2/default/v1/token", oReq, oResp)
IF (nSuccess == 0)
? oHttp:LastErrorText
oHttp:destroy()
oReq:destroy()
oResp:destroy()
RETURN
ENDIF
oSbResponseBody := CreateObject("Chilkat.StringBuilder")
oResp:GetBodySb(oSbResponseBody)
oJResp := CreateObject("Chilkat.JsonObject")
oJResp:LoadSb(oSbResponseBody)
oJResp:EmitCompact := 0
? "Response Body:"
? oJResp:Emit()
nRespStatusCode := oResp:StatusCode
? "Response Status Code = " + Str(nRespStatusCode)
IF (nRespStatusCode >= 400)
? "Response Header:"
? oResp:Header
? "Failed."
oHttp:destroy()
oReq:destroy()
oResp:destroy()
oSbResponseBody:destroy()
oJResp:destroy()
RETURN
ENDIF
// Sample JSON response:
// (Sample code for parsing the JSON response is shown below)
// {
// "access_token": "eyJraWQiO ... B2CnCLj7GRUW3mQ",
// "token_type": "Bearer",
// "expires_in": 3600,
// "scope": "customScope"
// }
// Sample code for parsing the JSON response...
// Use the following online tool to generate parsing code from sample JSON:
// Generate Parsing Code from JSON
cAccess_token := oJResp:StringOf("access_token")
cToken_type := oJResp:StringOf("token_type")
nExpires_in := oJResp:IntOf("expires_in")
cScope := oJResp:StringOf("scope")
oHttp:destroy()
oReq:destroy()
oResp:destroy()
oSbResponseBody:destroy()
oJResp:destroy()