# Unable to get oAuth token for client credential flow

**URL:** <https://discuss.konghq.com/t/unable-to-get-oauth-token-for-client-credential-flow/1462>\
**Category:** Questions\
**Created:** [July 13, 2018, 9:56am UTC](https://discuss.konghq.com/t/unable-to-get-oauth-token-for-client-credential-flow/1462 "2018-07-13T09:56:48Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ritesh\_Jha](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/ritesh_jha/32/1448_2.png) [@Ritesh\_Jha](https://discuss.konghq.com/u/Ritesh_Jha)\
**Post date:** [July 13, 2018, 9:56am UTC](https://discuss.konghq.com/t/unable-to-get-oauth-token-for-client-credential-flow/1462/1 "2018-07-13T09:56:48Z")

</div>

Hi,

I am using kong 0.14 with Postgres 9.6. After creating consumer, application, service, plugin and routes I tried to fetch oauth token but I am unable to get oauth2/token for client\_credentials flow.

My request is as below  
curl --insecure [https://localhost:8443/oauth2/token](https://localhost:8443/oauth2/token) -d “client\_id=tFn3WQ278RPpulDW&grant\_type=client\_credentials&client\_secret=V0271fN5vvl117vKViJVcgw”

I tried the same setup using Cassandra and it worked. Am I missing anything for Postgres ?

---

<div class="post-metadata">

**Author:** ![kikito](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/kikito/32/15_2.png) [@kikito](https://discuss.konghq.com/u/kikito)\
**Post date:** [July 13, 2018, 10:06am UTC](https://discuss.konghq.com/t/unable-to-get-oauth-token-for-client-credential-flow/1462/2 "2018-07-13T10:06:12Z")

</div>

Hi,

It’s difficult to know what is happening here whithout more information.

What response are you receiving to your request?

Does the nginx log show any error messages?

---

<div class="post-metadata">

**Author:** ![Ritesh\_Jha](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/ritesh_jha/32/1448_2.png) [@Ritesh\_Jha](https://discuss.konghq.com/u/Ritesh_Jha)\
**Post date:** [July 13, 2018, 11:15am UTC](https://discuss.konghq.com/t/unable-to-get-oauth-token-for-client-credential-flow/1462/3 "2018-07-13T11:15:02Z")

</div>

request command:  
curl --insecure [https://localhost:8443/oauth2/token](https://localhost:8443/oauth2/token) -d “client\_id=tFn3WQ278RPpulDW&grant\_type=client\_credentials&client\_secret=V0271fN5vvl117vKViJVcgw”

Response:  
HTTP/2 404  
date: Fri, 13 Jul 2018 11:11:15 GMT  
content-type: text/html; charset=UTF-8  
content-length: 233  
server: gunicorn/19.8.1  
access-control-allow-origin: \*  
access-control-allow-credentials: true  
via: kong/0.14.0  
x-kong-upstream-latency: 224  
x-kong-proxy-latency: 1

404 Not Found
# Not Found

The requested URL was not found on the server. If you entered the URL manually please check your spelling and try again.

nginx error: “POST /oauth2/token HTTP/1.1” 404 233

---

<div class="post-metadata">

**Author:** ![kikito](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/kikito/32/15_2.png) [@kikito](https://discuss.konghq.com/u/kikito)\
**Post date:** [July 13, 2018, 11:19am UTC](https://discuss.konghq.com/t/unable-to-get-oauth-token-for-client-credential-flow/1462/4 "2018-07-13T11:19:26Z")

</div>

That error seems to indicate that the oauth2 plugin was not installed. Can you check that it is?

---

<div class="post-metadata">

**Author:** ![Ritesh\_Jha](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/ritesh_jha/32/1448_2.png) [@Ritesh\_Jha](https://discuss.konghq.com/u/Ritesh_Jha)\
**Post date:** [July 13, 2018, 11:23am UTC](https://discuss.konghq.com/t/unable-to-get-oauth-token-for-client-credential-flow/1462/5 "2018-07-13T11:23:59Z")

</div>

I added oauth2 plugin at the service layer. Is der any other place I need to add ?

---

<div class="post-metadata">

**Author:** ![Ritesh\_Jha](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/ritesh_jha/32/1448_2.png) [@Ritesh\_Jha](https://discuss.konghq.com/u/Ritesh_Jha)\
**Post date:** [July 13, 2018, 12:08pm UTC](https://discuss.konghq.com/t/unable-to-get-oauth-token-for-client-credential-flow/1462/6 "2018-07-13T12:08:23Z")

</div>

from endpoint curl --request GET localhost:8001/plugins/ I m getting below response.

{  
“total”:1,  
“data”:[  
{  
“created\_at”:1531459338000,  
“config”:{  
“refresh\_token\_ttl”:1209600,  
“scopes”:[  
“read:location”  
],  
“mandatory\_scope”:true,  
“provision\_key”:“VAvvQuLSwffjeTcqXVmAOXKSiHdSawud”,  
“hide\_credentials”:false,  
“token\_expiration”:3600,  
“enable\_implicit\_grant”:false,  
“global\_credentials”:false,  
“anonymous”:"",  
“enable\_password\_grant”:false,  
“enable\_client\_credentials”:true,  
“enable\_authorization\_code”:false,  
“accept\_http\_if\_already\_terminated”:false,  
“auth\_header\_name”:“authorization”  
},  
“id”:“3b8166d9-f145-4c0b-8dcb”,  
“name”:“oauth2”,  
“service\_id”:“6dd03fec-a7fc-4ab2”,  
“enabled”:true  
}  
]  
}

---

<div class="post-metadata">

**Author:** ![jeremyjpj0916](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/jeremyjpj0916/32/1388_2.png) [@jeremyjpj0916](https://discuss.konghq.com/u/jeremyjpj0916)\
**Post date:** [July 13, 2018, 7:18pm UTC](https://discuss.konghq.com/t/unable-to-get-oauth-token-for-client-credential-flow/1462/7 "2018-07-13T19:18:37Z")

</div>

You need to call it against

[https://localhost:8443/ROUTE\_PATH/oauth2/token](https://localhost:8443/ROUTE_PATH/oauth2/token)

Every Oauth2 endpoint for token generation changes per proxy Unless you do what I described here:

> [@Enable OAuth2 for Multiple Services](https://discuss.konghq.com/t/enable-oauth2-for-multiple-services/1427/3):
>
> Here is what I do for my gateway and I consider it to be a pretty good practice(I think documentation on Kong for best practices here would be helpful some time as the default behavior I consider to be a bit ehhhh). Step 1. Create an route of /auth with a service pointing to some dummy backend URL(it will never get called). Enable the Oauth2 plugin on this proxy with global\_credentials set to true. You now have a clean endpoint like this to give to ALL clients for generating a Bearer token for …

---

<div class="post-metadata">

**Author:** ![Ritesh\_Jha](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/ritesh_jha/32/1448_2.png) [@Ritesh\_Jha](https://discuss.konghq.com/u/Ritesh_Jha)\
**Post date:** [July 14, 2018, 9:11am UTC](https://discuss.konghq.com/t/unable-to-get-oauth-token-for-client-credential-flow/1462/8 "2018-07-14T09:11:11Z")

</div>

Thanks for tips. It worked. Kong integration with Cassandra didn’t complain about this. I only faced this issue when I tried to do setup Kong using Postgres.

---

<div class="post-metadata">

**Author:** ![Ritesh\_Jha](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/ritesh_jha/32/1448_2.png) [@Ritesh\_Jha](https://discuss.konghq.com/u/Ritesh_Jha)\
**Post date:** [July 16, 2018, 6:55am UTC](https://discuss.konghq.com/t/unable-to-get-oauth-token-for-client-credential-flow/1462/9 "2018-07-16T06:55:36Z")

</div>

@jeremyjpj0916

After getting token when I call route its throwing error “The access token is invalid or has expired”. I added details here [Error while calling routes using oAuth2 token](https://discuss.konghq.com/t/error-while-calling-routes-using-oauth2-token/1476)

---

<div class="post-metadata">

**Author:** ![Ritesh\_Jha](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/ritesh_jha/32/1448_2.png) [@Ritesh\_Jha](https://discuss.konghq.com/u/Ritesh_Jha)\
**Post date:** [July 16, 2018, 1:40pm UTC](https://discuss.konghq.com/t/unable-to-get-oauth-token-for-client-credential-flow/1462/10 "2018-07-16T13:40:09Z")

</div>

ignore my above query. I found reason.

---

<div class="post-metadata">

**Author:** ![Abhishek\_Ghosh](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/abhishek_ghosh/32/1427_2.png) [@Abhishek\_Ghosh](https://discuss.konghq.com/u/Abhishek_Ghosh)\
**Post date:** [October 23, 2019, 4:28am UTC](https://discuss.konghq.com/t/unable-to-get-oauth-token-for-client-credential-flow/1462/11 "2019-10-23T04:28:46Z")

</div>

Hi Ritesh,

I am facing similar problem but my code is in scala. here is what I am doing. However when I try in POSTMAN it work absolutely fine. Can you see what I am doing wrong ?

case class credentials (  
scope: String, //="/consent.create /consent.read /library.read"  
grant\_type: String //=“client\_credentials”  
)

```
val id="<kEY>"
val secret="<SECRET>"

val authString = Base64.getEncoder.encodeToString(s"$id:$secret".getBytes(StandardCharsets.UTF_8))

```

val cred = new credentials("/consent.create /consent.read /library.read", “client\_credentials”)

```
val body = new Gson().toJson("1:3")
//val body = gson.toJson(cred)
val endpoint = "https://<HOSTNAME>/api/v1/oauth/v1/token"
val url = endpoint //+ "&client_id=" + + "&client_secret=" + _clientSecret
println(url)
val client = HttpClientBuilder.create().build()
val post = new HttpPost(url)
post.addHeader("Content-Type", "application/x-www-form-urlencoded")
post.addHeader("Authorization", "Basic " + authString)

post.addHeader("grant_type", "client_credentials")
post.addHeader("scope", "<HOSTNAME>/consent.create <HOSTNAME>/consent.read <HOSTNAME>/library.read")

post.setEntity(new StringEntity(body))
println(post.getAllHeaders.foreach(println))
val response = client.execute(post)
println("response:" + response)
```

---

<div class="post-metadata">

**Author:** ![Ritesh\_Jha](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/ritesh_jha/32/1448_2.png) [@Ritesh\_Jha](https://discuss.konghq.com/u/Ritesh_Jha)\
**Post date:** [October 30, 2019, 3:27pm UTC](https://discuss.konghq.com/t/unable-to-get-oauth-token-for-client-credential-flow/1462/12 "2019-10-30T15:27:53Z")

</div>

sorry for the late reply. Are you still getting error?  
In my case I added a route with path “/oauth2/token” and set this as global level.  
Please check.
