DevNet Associate (DEVASC) v1.0Understanding and Using APIsMedium

A network automation developer is integrating a new application with a Cisco DNA Center API. The API uses OAuth 2.0 for authorization. The application is a backend service that needs to access the DNA Center API on its own behalf, without any direct user interaction. Which OAuth 2.0 grant type is most appropriate for this scenario?

  1. AAuthorization Code Grant
  2. BClient Credentials Grant
  3. CImplicit Grant
  4. DResource Owner Password Credentials Grant
Show answer & explanation

Correct answer: B. Client Credentials Grant

The Client Credentials Grant is specifically designed for machine-to-machine authentication where a client (e.g., a backend service) needs to access protected resources on its own behalf, without an end-user present. The client authenticates directly with the authorization server using its client ID and client secret.

Why the other options are wrong

  • A. Authorization Code Grant is for web applications with a user interface, requiring user interaction to grant consent.
  • C. Implicit Grant is for single-page applications or mobile apps, where tokens are returned directly to the client, considered less secure now.
  • D. Resource Owner Password Credentials Grant uses the user's username/password directly, which is generally discouraged due to security risks and lack of flexibility.

OAuth 2.0 Client Credentials Grant

An OAuth 2.0 grant type used by confidential clients to obtain an access token using only their client credentials, without involving an end-user.

  • Suitable for machine-to-machine (server-to-server) communication.
  • Client authenticates directly with the authorization server using `client_id` and `client_secret`.
  • No user interaction is involved in the authorization process.
  • Grants access to resources owned by the client application itself, not a specific end-user.

Memory trick: Different keys for different doors: who is asking for access?

More Understanding and Using APIs questions