Sample code for 30+ languages & platforms
Tcl Requires Chilkat v11.0.0+

Azure OAuth2 Client Credentials Grant Flow

See more OAuth2 Examples

Demonstrates how to get an OAuth2 access token for an Azure Registered App using the Client Credentials Grant Flow.

Note: Your Azure app must be registered as a single-tenant app to use client credentials.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

#  This example requires the Chilkat API to have been previously unlocked.
#  See Global Unlock Sample for sample code.

set http [new_CkHttp]

set req [new_CkHttpRequest]

CkHttpRequest_AddParam $req "client_secret" "CLIENT_SECRET"
CkHttpRequest_AddParam $req "client_id" "CLIENT_ID"

#  See Understanding Scopes in Azure OAuth2 Client Credentials Flow
CkHttpRequest_AddParam $req "scope" "https://graph.microsoft.com/.default"

CkHttpRequest_AddParam $req "grant_type" "client_credentials"

#  Note: Your Azure app must be registered as a single-tenant app to use client credentials.
#  Use your own tenant ID, for example 4d8fdd66-66d1-43b0-ae5c-e31b4b7de5cd
set url "https://login.microsoftonline.com/TENANT_ID/oauth2/v2.0/token"

CkHttpRequest_put_HttpVerb $req "POST"
CkHttpRequest_put_ContentType $req "application/x-www-form-urlencoded"

set resp [new_CkHttpResponse]

set success [CkHttp_HttpReq $http $url $req $resp]
if {$success == 0} then {
    puts [CkHttp_lastErrorText $http]
    delete_CkHttp $http
    delete_CkHttpRequest $req
    delete_CkHttpResponse $resp
    exit
}

set statusCode [CkHttpResponse_get_StatusCode $resp]
puts "Response status code = $statusCode"

set json [new_CkJsonObject]

CkJsonObject_Load $json [CkHttpResponse_bodyStr $resp]

CkJsonObject_put_EmitCompact $json 0
puts [CkJsonObject_emit $json]

#  Sample successful output:

#  {
#    "token_type": "Bearer",
#    "expires_in": 3599,
#    "ext_expires_in": 3599,
#    "access_token": "eyJ0eX...K0jOERg"
#  }

if {$statusCode == 200} then {
    CkJsonObject_WriteFile $json "qa_data/tokens/azureClientCredentialsToken.json"
    puts "Success."
} else {
    puts "Failed."
}


delete_CkHttp $http
delete_CkHttpRequest $req
delete_CkHttpResponse $resp
delete_CkJsonObject $json