ReferenceSequence diagrams
Client Credentials (M2M)
Server-to-server OAuth2 flow
Properties
- No user involved. The
subclaim is theclient_id, not a user UUID. - No refresh token. Worker just requests a new one when needed.
- No ID token. Pure machine identity.
- Short TTL (1 hour default). Cache and renew on expiry.