OAuth client credentials, scopes, audience
CONCEPTS:OAuth 2.0 Authorization
Question Variations
- "When is client credentials the right OAuth grant?"
- "How do scopes differ from an audience?"
- "Why should an API validate both scope and audience?"
Why This Is Asked
This distinguishes user-delegated authorization from service-to-service authorization. Interviewers want to see whether you can choose client credentials appropriately, restrict machine tokens to the intended API and permissions, and protect the client credential as a production secret.
Key Concepts
- Client credentials: A client authenticates as itself; there is no end-user authorization step.
- Scopes: Permissions requested and granted to the token.
- Audience: The resource server that is expected to accept the token.
- Credential protection: Prefer workload identity or asymmetric client authentication over broadly shared static secrets.
Question Variations
- “When is client credentials the right OAuth grant?”
- “How do scopes differ from an audience?”
- “Why should an API validate both scope and audience?”