Beta

Create a tenant

A new tenant starts with its own users, OAuth settings, audit history and logs. You are its first Tenant Admin.

BTL Admin

L29 · OAUTH 2.0

Get a token as the client

Use the client credentials grant with curl, then see the token endpoint refuse a wrong secret and a scope the client was not given.

Planned

Steps

  1. Register a confidential client that may use the client credentials grant and one scope.

    What the server will check: The client exists in your tenant with that grant.

  2. Request a token for that scope with curl, authenticating with the client secret.

    What the server will check: A successful client credentials exchange for your client.

    No user or browser takes part. The token represents the client itself.

  3. Send the same request with a wrong secret.

    What the server will check: The token endpoint rejected the client.

  4. Ask for a scope the client was not given.

    What the server will check: The request was refused for that scope.

    The client's credentials unlock only what its registration allows, so its scopes should stay narrow.

When it opens

This lab is planned. It opens when these are in place:

  • Lab setup and cleanup in your test tenant

The server checks your test tenant's history for this attempt. You can review the events yourself in your tenant's Audit and Logs.

Learn the theory

Back to all labs

We value your privacy

We use cookies and similar technologies to enhance your browsing experience, and analytics to understand our traffic. By clicking "Allow All", you consent to optional analytics. Cookie Policy

The Lab