Skip to content

feat: add client credentials token support for M2M - #138

Open
kishore7snehil wants to merge 2 commits into
feat/obo-token-storagefrom
feat/m2m-client-credentials
Open

kishore7snehil wants to merge 2 commits into
feat/obo-token-storagefrom
feat/m2m-client-credentials

Conversation

@kishore7snehil

Copy link
Copy Markdown
Contributor

📋 Changes

This PR adds get_client_credentials_token() to ApiClient for obtaining machine-to-machine access tokens with the OAuth 2.0 client credentials grant. When a token store is configured, the result is cached so repeat calls within the token's lifetime skip the network round-trip.

✨ Features

  • Client Credentials Token: New get_client_credentials_token(audience, scope=None) method that authenticates with HTTP Basic using the configured client_id and client_secret.
  • M2M Caching: When token_store is set, tokens are cached per tenant, client, audience, and scope set. Store read and write failures are logged and fall back to a fresh exchange.
  • Type Safety: New ClientCredentialsTokenResult TypedDict.

🔧 API Changes

  • New method: ApiClient.get_client_credentials_token()
  • New type: ClientCredentialsTokenResult (TypedDict)
  • New error: GetClientCredentialsTokenError, raised when client credentials are not configured or the token endpoint is missing from discovery metadata

📖 Documentation

  • Updated README.md with a client credentials section
  • Updated EXAMPLES.md with a client credentials example

🧪 Testing

  • This change adds test coverage
  • This change has been tested on the latest version of the platform/language

Contributor Checklist

🤖 Generated with Claude Code

Add an ApiClient method to obtain a client credentials (M2M) access token
for server-to-server calls using the OAuth 2.0 client credentials grant.
The method authenticates via HTTP Basic and caches the result in a
configured token_store keyed by audience and scope set, so a repeat call
within the token's lifetime skips the network round-trip. Add the
ClientCredentialsTokenResult type and GetClientCredentialsTokenError, and
document the method in the README and examples.

Co-Authored-By: Claude <noreply@anthropic.com>
Comment thread src/auth0_api_python/api_client.py Fixed
Co-Authored-By: Claude <noreply@anthropic.com>
@kishore7snehil
kishore7snehil marked this pull request as ready for review October 6, 2026 06:50
@kishore7snehil
kishore7snehil requested a review from a team as a code owner October 6, 2026 06:50

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants