Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yah, that's the OAuth Client Credentials flow but as noted, you still have a static set of creds that are required to generate the short lived access token. Besides being useful for being able to limit scope in some circumstances, the main point of the client cred flow is to appease eager sec arch's who insist on OAuth.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: