Sample code for 30+ languages & platforms
Xbase++ Requires Chilkat v11.0.0+

Azure OAuth2 Client Credentials Grant Flow

See more OAuth2 Examples

Demonstrates how to get an OAuth2 access token for an Azure Registered App using the Client Credentials Grant Flow.

Note: Your Azure app must be registered as a single-tenant app to use client credentials.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oHttp
LOCAL oReq
LOCAL cUrl
LOCAL oResp
LOCAL nStatusCode
LOCAL oJson

nSuccess := 0

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

oHttp := CreateObject("Chilkat.Http")

oReq := CreateObject("Chilkat.HttpRequest")
oReq:AddParam("client_secret", "CLIENT_SECRET")
oReq:AddParam("client_id", "CLIENT_ID")

//  See Understanding Scopes in Azure OAuth2 Client Credentials Flow
oReq:AddParam("scope", "https://graph.microsoft.com/.default")

oReq:AddParam("grant_type", "client_credentials")

//  Note: Your Azure app must be registered as a single-tenant app to use client credentials.
//  Use your own tenant ID, for example 4d8fdd66-66d1-43b0-ae5c-e31b4b7de5cd
cUrl := "https://login.microsoftonline.com/TENANT_ID/oauth2/v2.0/token"

oReq:HttpVerb := "POST"
oReq:ContentType := "application/x-www-form-urlencoded"

oResp := CreateObject("Chilkat.HttpResponse")
nSuccess := oHttp:HttpReq(cUrl, oReq, oResp)
IF (nSuccess == 0)
    ? oHttp:LastErrorText
    oHttp:destroy()
    oReq:destroy()
    oResp:destroy()
    RETURN
ENDIF

nStatusCode := oResp:StatusCode
? "Response status code = " + Str(nStatusCode)

oJson := CreateObject("Chilkat.JsonObject")
oJson:Load(oResp:BodyStr)

oJson:EmitCompact := 0
? oJson:Emit()

//  Sample successful output:

//  {
//    "token_type": "Bearer",
//    "expires_in": 3599,
//    "ext_expires_in": 3599,
//    "access_token": "eyJ0eX...K0jOERg"
//  }

IF (nStatusCode == 200)
    oJson:WriteFile("qa_data/tokens/azureClientCredentialsToken.json")
    ? "Success."
ELSE
    ? "Failed."
ENDIF

oHttp:destroy()
oReq:destroy()
oResp:destroy()
oJson:destroy()