# Getting user's access-token using clientId/secret

**URL:** <https://forum.keycloak.org/t/getting-users-access-token-using-clientid-secret/28237>\
**Category:** Getting advice\
**Created:** [October 8, 2024, 1:32pm UTC](https://forum.keycloak.org/t/getting-users-access-token-using-clientid-secret/28237 "2024-10-08T13:32:00Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![hungalabuna](https://avatars.discourse-cdn.com/v4/letter/h/a9adbd/32.png) [@hungalabuna](https://forum.keycloak.org/u/hungalabuna)\
**Post date:** [October 8, 2024, 1:32pm UTC](https://forum.keycloak.org/t/getting-users-access-token-using-clientid-secret/28237/1 "2024-10-08T13:32:00Z")

</div>

Hello,

We got java spring app where we use keycloak-admin-client lib.  
Usualy we use user pass and user name to get his access-token and refresh-token but now we got new requirements:  
How to get user access-token but using keycloak client data (I got access to clientId and client secret) ?

---

<div class="post-metadata">

**Author:** ![Carl](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/carl/32/10443_2.png) [@Carl](https://forum.keycloak.org/u/Carl)\
**Post date:** [October 8, 2024, 4:07pm UTC](https://forum.keycloak.org/t/getting-users-access-token-using-clientid-secret/28237/2 "2024-10-08T16:07:46Z")

</div>

It sounds like you might want a Keycloak Service Account. This gives you an Access Token when specifying only client\_id and client\_secret. Be advised though that this isn’t a real user so the preferred\_username and realm\_roles fields may look different.

---

<div class="post-metadata">

**Author:** ![embesozzi](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/embesozzi/32/12390_2.png) [@embesozzi](https://forum.keycloak.org/u/embesozzi)\
**Post date:** [October 8, 2024, 7:15pm UTC](https://forum.keycloak.org/t/getting-users-access-token-using-clientid-secret/28237/3 "2024-10-08T19:15:58Z")

</div>

Just to add the link to the standard: if you want a token in the context of the client (app), it is related to client credentials grant [1].

[1] [RFC 6749 - The OAuth 2.0 Authorization Framework](https://datatracker.ietf.org/doc/html/rfc6749#section-1.3.4)
