# keycloak with oauth2 client credential grant for authenticate external clients(services/applications) to my public API

**URL:** <https://forum.keycloak.org/t/keycloak-with-oauth2-client-credential-grant-for-authenticate-external-clients-services-applications-to-my-public-api/568>\
**Category:** Getting advice\
**Created:** [November 29, 2019, 2:40pm UTC](https://forum.keycloak.org/t/keycloak-with-oauth2-client-credential-grant-for-authenticate-external-clients-services-applications-to-my-public-api/568 "2019-11-29T14:40:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tal](https://avatars.discourse-cdn.com/v4/letter/t/54ee81/32.png) [@Tal](https://forum.keycloak.org/u/Tal)\
**Post date:** [November 29, 2019, 2:40pm UTC](https://forum.keycloak.org/t/keycloak-with-oauth2-client-credential-grant-for-authenticate-external-clients-services-applications-to-my-public-api/568/1 "2019-11-29T14:40:04Z")

</div>

As I understand it, oauth2 client credential grant type should be used in a case where some client app/service needs access to some resource without user interaction.

This sounds good also in a case where the client is an external client and the resource service is a public API service.

Please correct me if I’m wrong, or if there is a “better” or more “standard” way.

I’m trying to find some resource that explains how to use keycloak for such case, but the only one I found is [this stack-overflow answer](https://stackoverflow.com/questions/52230634/issuing-api-keys-using-keycloak/53178757#53178757).

As I understand, I need to create a client for my Public API service with “Service Accounts Enabled: ON”. And a bearer-only client for each external client that want to access to the public API. Am I right?

Please advice, Thanks!

---

<div class="post-metadata">

**Author:** ![stianst](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/stianst/32/16_2.png) [@stianst](https://forum.keycloak.org/u/stianst)\
**Post date:** [December 2, 2019, 9:33am UTC](https://forum.keycloak.org/t/keycloak-with-oauth2-client-credential-grant-for-authenticate-external-clients-services-applications-to-my-public-api/568/2 "2019-12-02T09:33:22Z")

</div>

Yes, you are correct. Client credential grant with a confidential client with service accounts enabled is the right way to obtain tokens on-behalf of a service (non-human).

---

<div class="post-metadata">

**Author:** ![joao-rebelo](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/joao-rebelo/32/3487_2.png) [@joao-rebelo](https://forum.keycloak.org/u/joao-rebelo)\
**Post date:** [December 2, 2019, 6:14pm UTC](https://forum.keycloak.org/t/keycloak-with-oauth2-client-credential-grant-for-authenticate-external-clients-services-applications-to-my-public-api/568/3 "2019-12-02T18:14:53Z")

</div>

would there be any recomendation for a simple Java library that fetches the tokens?  
I’m running on a simple Java (“void main”) application with picocli, and would like to get the service account tokens, and then use them to access my resource server…  
I’ve been searching for days on an easy way to do this, but all solutions are integrated on some kind of framework… haven’t found a simple one yet.  
I’m now trying pac4j, but it’s feeling like another dead end… ☹

Thanks for any help.
