# Keycloak - client credentials grant violation of OAuth2 standard (RFC6749)?

**URL:** <https://forum.keycloak.org/t/keycloak-client-credentials-grant-violation-of-oauth2-standard-rfc6749/3502>\
**Category:** Miscellanaeous\
**Created:** [June 26, 2020, 7:40am UTC](https://forum.keycloak.org/t/keycloak-client-credentials-grant-violation-of-oauth2-standard-rfc6749/3502 "2020-06-26T07:40:19Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![ping](https://avatars.discourse-cdn.com/v4/letter/p/f14d63/32.png) [@ping](https://forum.keycloak.org/u/ping)\
**Post date:** [June 26, 2020, 7:40am UTC](https://forum.keycloak.org/t/keycloak-client-credentials-grant-violation-of-oauth2-standard-rfc6749/3502/1 "2020-06-26T07:40:19Z")

</div>

Hi,

For the client credentials grant, Keycloak (at least 9.0.x) do issue a ‘refresh token’ which violate the RFC

- which state that “A refresh token SHOULD NOT be included.”  
([https://tools.ietf.org/html/rfc6749#page-4.4.3](https://tools.ietf.org/html/rfc6749#page-4.4.3))

Is it possible to configure keycloak to do not issue ‘refresh token’ for client credentials grant for standard conformance?

thanks.
