tencent cloud

Tencent OneID Identity Security

Client Credentials Mode

Download
Focus Mode
Font Size
Last updated: 2026-08-26 15:36:23
AI-Translated

API Description

Obtain an Access Token using the OAuth client credentials mode (client_credentials).

Supported Application Types

Web applications and M2M applications.

Request Method

POST

Request path

/oauth2/token

Request Content-Type

application/x-www-form-urlencoded

Request Example

POST /oauth2/token HTTP/1.1
Host: sample.portal.tencentciam.com
Content-Type: application/x-www-form-urlencoded

grant_type=client_credentials&client_id=TENANT_CLIENT_ID&client_secret=TENANT_CLIENT_SECRET&scope=identity_proofing

Request Parameters

Parameter
No
Description
grant_type
false
Enter the fixed value client_credentials.
client_id
false
The application's client_id. You can refer to the corresponding "Client Id" on Application Management Page > Select the Specified Application > Click Application Configuration >.
client_secret
false
The application's client_secret. You can refer to the corresponding "client_secret" on Application Management Page > Select the Specified Application > Click Application Configuration >.
scope
true
Request the authorized scope. Separate multiple scopes with spaces.

Normal Response Example

HTTP/1.1 200 OK
Content-Type: application/json;charset=UTF-8

{
"access_token" : "eyJraWQiOiJmOTY5NGQ5My1kNTQxLTQ5ODUtODhkYy00MjIyOTg3MzAwOGUiLCJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJzdWIiOiJURU5BTlRfQ0xJRU5UX0lEIiwiYXVkIjoiVEVOQU5UX0NMSUVOVF9JRCIsIm5iZiI6MTY0MDU4ODgyOCwic2NvcGUiOlsiaWRlbnRpdHlfcHJvb2ZpbmciXSwiaXNzIjoiaHR0cHM6XC9cL3NhbXBsZS5wb3J0YWwudGVuY2VudGNpYW0uY29tIiwiZXhwIjoxNjQwNTg5MTI4LCJpYXQiOjE2NDA1ODg4MjgsImp0aSI6Ijk5MzliYzNmLTVlZGYtNDZjMy04ZjVjLTJiMWRjMWFjZmE5MCJ9.D8khbU3BkWTHD6sRTY9M_bbRq7AF4MGina2S1ycFA2HOUo-k_P_f81V4fP1DLO7n-1_5em_Dmxo768wsFcvUIYWRlSLh91kXPTyBV5mHt6IZRnT3eMpqTiMKC_ubzUc_7DSpE8-99-CpfrQ19hcpMwkoLYh1dwYjUJB6xyZPzqlezrHy4unUHLTpyjGeecgNNLUScY9W0diGxVnbsMuTW7T00OsltNoJj11qtOllbh5kd1B4umvA3UJpGucVMZQ2YTvltHyDBefWabP4ektzktAwDTALGIu1EsQfb5j9Rru3R0L0nAvjT8HiIqthLvvMdkjXAW983zj0yCPe3GqF3g",
"scope" : "identity_proofing",
"token_type" : "Bearer",
"expires_in" : 299
}

Response Parameters

Parameter
Data Type
Description
access_token
String
Access Token (JWT).
token_type
String
The Token type. Currently, the fixed value Bearer is returned.
expires_in
Number
The validity period of the Access Token, in seconds.
scope
String
The Scope of the Access Token.
Note:
The response for the client credentials mode does not include a Refresh Token. When the Access Token expires, the application must call this API again to obtain a new Access Token.

Exception Response Example

The application does not exist, is not enabled, or the application key verification failed.
HTTP/1.1 401 Unauthorized
Content-Type: application/json;charset=UTF-8

{
"error" : "invalid_client"
}
The application does not have permission to obtain a Token using the client_credentials mode.
HTTP/1.1 400 Bad Request
Content-Type: application/json;charset=UTF-8

{
"error" : "unauthorized_client"
}
The scope parameter is incorrect or exceeds the application's permissions.
HTTP/1.1 400 Bad Request
Content-Type: application/json;charset=UTF-8

{
"error" : "invalid_scope"
}


Help and Support

Was this page helpful?

Help us improve! Rate your documentation experience in 5 mins.

Feedback