DevNet Associate (DEVASC) v1.0Understanding and Using APIsMedium

A developer needs to integrate a new application with a Cisco Identity Services Engine (ISE) API. The ISE API documentation specifies that OAuth 2.0 with the Client Credentials Grant flow should be used for machine-to-machine communication. Which sequence of steps correctly outlines this OAuth 2.0 flow?

  1. AClient generates a temporary token -> Sends temporary token to authorization server -> Authorization server validates and issues a permanent access token to client.
  2. BClient sends client ID and client secret to authorization server token endpoint -> Authorization server authenticates client -> Authorization server issues access token directly to client.
  3. CClient redirects user to authorization server -> User authorizes -> Authorization server redirects user back to client with authorization code -> Client exchanges code for access token.
  4. DClient sends client ID and client secret to resource server -> Resource server authenticates client -> Resource server issues access token directly to client.
Show answer & explanation

Correct answer: B. Client sends client ID and client secret to authorization server token endpoint -> Authorization server authenticates client -> Authorization server issues access token directly to client.

The Client Credentials Grant is specifically designed for machine-to-machine authentication where there is no user involvement. The client authenticates directly with the authorization server using its `client_id` and `client_secret` to obtain an access token.

Why the other options are wrong

  • A. This is not a standard OAuth 2.0 grant type. OAuth flows involve specific credential exchanges, not arbitrary 'temporary tokens'.
  • C. This describes the Authorization Code Grant flow, which involves a user's browser.
  • D. The client interacts with the authorization server (not resource server) to get an access token.

OAuth 2.0 Client Credentials Grant

An OAuth 2.0 authorization grant type used by clients to obtain an access token directly from the authorization server using only their own 'client_id' and 'client_secret', without user involvement.

  • Ideal for machine-to-machine (server-to-server) communication.
  • No user interaction or browser redirects involved.
  • Client authenticates itself to the authorization server.

Memory trick: OAuth Grants: Codes for Users, Clients for Machines.

More Understanding and Using APIs questions