Beta

Create a tenant

A new tenant starts with its own users, OAuth settings, audit history and logs. You are its first Tenant Admin.

BTL Admin

L32 · OAUTH 2.0

One method per client

Authenticate a confidential client the registered way, then see the token endpoint refuse a wrong secret and a secret sent the wrong way.

Planned

Steps

  1. Request a token with curl, sending the client ID and secret in an HTTP Basic header.

    What the server will check: A successful token request for your confidential client.

  2. Send the same request with one character of the secret changed.

    What the server will check: The token endpoint rejected the client.

    The response does not say which part was wrong, so it gives nothing away to someone guessing.

  3. Send the correct secret in the request body instead of the header.

    What the server will check: The token endpoint refused the request.

    Your client is registered for HTTP Basic. Accepting another method would give its credential a second way in.

When it opens

This lab is planned. It opens when these are in place:

  • Lab setup and cleanup in your test tenant

The server checks your test tenant's history for this attempt. You can review the events yourself in your tenant's Audit and Logs.

Learn the theory

Back to all labs

We value your privacy

We use cookies and similar technologies to enhance your browsing experience, and analytics to understand our traffic. By clicking "Allow All", you consent to optional analytics. Cookie Policy

The Lab