{
    "componentChunkName": "component---src-pages-blog-markdown-remark-fields-slug-js",
    "path": "/blog/machine-to-machine-authentication",
    "result": {"data":{"markdownRemark":{"html":"<p><strong>When you think of authentication, your mind probably jumps to the classic user-to-machine scenario — like logging into your favorite social media app or checking your bank account. You know the drill: type in your username, punch in your password, and hope you didn’t forget it (again).</strong></p>\n<p>But humans aren’t the only ones logging in — machines do it too, and they’re far busier than we are. As we go about our day (and even while we sleep), machines are constantly exchanging data behind the scenes.</p>\n<p>This non-stop chatter is called <strong>machine-to-machine (M2M) communication</strong>, and just like with any digital conversation, we need to make sure only the right participants have access. That’s why we authenticate ourselves before accessing certain information — and machines need to do the same to keep sneaky bad actors from getting their hands on sensitive data.</p>\n<p>Enter <strong>machine-to-machine (M2M) authentication</strong> — the key to ensuring machines can securely prove they’re who they claim to be.</p>\n<p>Let’s boot up and explore the world of machines.  🤖</p>\n<p><img src=\"https://media3.giphy.com/media/v1.Y2lkPTc5MGI3NjExYjR4dXE5Zmg5MDRoazdtNG9hZ2o1d3RleTY4bHRiOXh4dXhjdDJhYyZlcD12MV9pbnRlcm5hbF9naWZfYnlfaWQmY3Q9Zw/Yn23Blov9gNxmrY74K/giphy.gif\" alt=\"A GIF of robot arms working together\"></p>\n<div\n              class=\"gatsby-code-button-container\"\n              data-toaster-id=\"92789679283890810000\"\n              data-toaster-class=\"gatsby-code-button-toaster\"\n              data-toaster-text-class=\"gatsby-code-button-toaster-text\"\n              data-toaster-text=\"Copied!\"\n              data-toaster-duration=\"3500\"\n              onClick=\"copyToClipboard(`tight: true\ntoHeading: 3`, `92789679283890810000`)\"\n            >\n              <div\n                class=\"gatsby-code-button\"\n                data-tooltip=\"\"\n              >\n                <svg class=\"gatsby-code-button-icon\" xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\"><path fill=\"none\" d=\"M0 0h24v24H0V0z\"/><path d=\"M16 1H2v16h2V3h12V1zm-1 4l6 6v12H6V5h9zm-1 7h5.5L14 6.5V12z\"/></svg>\n              </div>\n            </div>\n<div class=\"table-of-contents\">\n<ul>\n<li><a href=\"#what-is-a-machine\">What is a Machine?</a></li>\n<li><a href=\"#m2m-communication\">M2M Communication</a>\n<ul>\n<li><a href=\"#examples-of-m2m-communication\">Examples of M2M Communication:</a></li>\n</ul>\n</li>\n<li><a href=\"#m2m-authentication\">M2M Authentication</a></li>\n<li><a href=\"#m2m-authentication-vs-m2m-authorization\">M2M Authentication vs M2M Authorization</a></li>\n<li><a href=\"#-a-closer-look-at-how-m2m-authentication-works-\">✨ A Closer Look at How M2M Authentication Works ✨</a>\n<ul>\n<li><a href=\"#1-device-identification-and-authentication\">1. Device Identification and Authentication</a></li>\n<li><a href=\"#2-access-token-issuance\">2. Access Token Issuance</a></li>\n<li><a href=\"#3-secure-communication\">3. Secure Communication</a></li>\n<li><a href=\"#4-communication-standards\">4. Communication Standards</a></li>\n<li><a href=\"#5-enhanced-security-and-efficiency\">5. Enhanced Security and Efficiency</a></li>\n<li><a href=\"#6-autonomous-operations\">6. Autonomous Operations</a></li>\n<li><a href=\"#-step-by-step-the-client-credentials-grant-flow\">🚀 Step-by-Step: The Client Credentials Grant Flow</a></li>\n</ul>\n</li>\n<li><a href=\"#why-is-machine-to-machine-authentication-important-%EF%B8%8F\">Why Is Machine-to-Machine Authentication Important? 🛡️</a>\n<ul>\n<li><a href=\"#1-prevents-unauthorized-access\">1. Prevents Unauthorized Access</a></li>\n<li><a href=\"#2-protect-sensitive-data\">2. Protect Sensitive Data</a></li>\n<li><a href=\"#3-enables-scalable-systems\">3. Enables Scalable Systems</a></li>\n<li><a href=\"#4-ensures-compliance\">4. Ensures Compliance</a></li>\n<li><a href=\"#5-improves-operational-efficiency\">5. Improves Operational Efficiency</a></li>\n</ul>\n</li>\n<li><a href=\"#how-to-secure-your-machine-communication-with-supertokens\">How to Secure Your Machine Communication With SuperTokens</a></li>\n<li><a href=\"#steps-to-implementing-m2m-authentication-with-supertokens--super-simple-set-up\">Steps to Implementing M2M Authentication with SuperTokens — Super Simple Set Up</a>\n<ul>\n<li><a href=\"#-step-1-enable-oauth2-in-supertokens-dashboard\">🚀 Step 1: Enable OAuth2 in SuperTokens Dashboard</a></li>\n<li><a href=\"#-step-2-create-oauth2-clients\">🔧 Step 2: Create OAuth2 Clients</a></li>\n<li><a href=\"#%EF%B8%8F-step-3-single-app-vs-multi-app-setup\">🏗️ Step 3: Single App vs Multi App Setup</a></li>\n<li><a href=\"#-step-4-set-up-the-authorization-service\">🔐 Step 4: Set Up the Authorization Service</a></li>\n<li><a href=\"#-step-5-generate-access-tokens\">🔄 Step 5: Generate Access Tokens</a></li>\n<li><a href=\"#-step-6-verify-an-access-token\">✅ Step 6: Verify an Access Token</a></li>\n<li><a href=\"#-step-7-example-of-two-services-communicating-by-using-m2m\">🌍 Step 7: Example of Two Services Communicating By Using M2M</a></li>\n</ul>\n</li>\n<li><a href=\"#conclusion\">Conclusion</a></li>\n</ul>\n</div>\n<h2 id=\"what-is-a-machine\" style=\"position:relative;\"><a href=\"#what-is-a-machine\" aria-label=\"what is a machine permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>What is a Machine?</h2>\n<p>In machine-to-machine communication, the term “machine” covers a lot of ground. It can mean servers, applications, APIs, Internet of Things (IoT) devices, or even cronjobs.</p>\n<p>For this article, we’re focusing on authentication between services — not IoT gadgets like robots or smart home devices.</p>\n<h2 id=\"m2m-communication\" style=\"position:relative;\"><a href=\"#m2m-communication\" aria-label=\"m2m communication permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>M2M Communication</h2>\n<p>Simply put, M2M communication is the automated exchange of information between machines — no human involvement required. ❌🧑</p>\n<h3 id=\"examples-of-m2m-communication\" style=\"position:relative;\"><a href=\"#examples-of-m2m-communication\" aria-label=\"examples of m2m communication permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Examples of M2M Communication:</h3>\n<ul>\n<li>☁️ A cloud service retrieving data from a database</li>\n<li>🔄 An API fetching information from another service</li>\n<li>📡 Two or more IoT devices syncing their status</li>\n</ul>\n<p>Unlike human-to-machine communication (like logging into a website with a username and password 💻), where a <strong>person’s</strong> identity needs to be verified, M2M communication requires authentication methods that confirm the <strong>identity of a machine</strong>, instead.</p>\n<h2 id=\"m2m-authentication\" style=\"position:relative;\"><a href=\"#m2m-authentication\" aria-label=\"m2m authentication permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>M2M Authentication</h2>\n<p>Machine-to-machine (M2M) authentication is the process of verifying the identity of a machine that’s trying to communicate with another machine. While this sounds straightforward, it covers a broad range of scenarios.</p>\n<p>M2M communication — and therefore authentication — can happen in both hardware and software.</p>\n<p>Take the Mars Rover, for example. This iconic piece of hardware needs to communicate securely with other systems to send data back to Earth — and those systems must authenticate each other to ensure the data isn’t intercepted or altered.</p>\n<p>In software, M2M communication happens constantly. Services exchange data, make requests, and pass information back and forth — and this needs to happen securely. Authenticating these services ensures sensitive data doesn’t end up in the wrong hands. 🦾</p>\n<p><strong>Common methods include:</strong></p>\n<ul>\n<li>API keys</li>\n<li>OAuth tokens</li>\n<li>Mutual TLS (mTLS)</li>\n<li>Cryptographic certificates</li>\n</ul>\n<table>\n<thead>\n<tr>\n<th><strong>User Authentication 👤</strong></th>\n<th><strong>M2M Authentication 🤖</strong></th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Requires human interaction (e.g., login form, password)</td>\n<td>Fully automated (no human input)</td>\n</tr>\n<tr>\n<td>Uses username/password or social logins (OAuth Authorization Code Flow)</td>\n<td>Uses <strong>client ID and secret</strong> or service accounts</td>\n</tr>\n<tr>\n<td>Access is tied to a user session</td>\n<td>Access is tied to a <strong>machine identity</strong></td>\n</tr>\n<tr>\n<td>Example: A user logs into a social media site and gets a session token</td>\n<td>Example: A backend service calls an API by using a client credentials token</td>\n</tr>\n</tbody>\n</table>\n<p>By ensuring machines can confidently identify each other, M2M authentication plays a crucial role in keeping modern digital ecosystems secure.</p>\n<h2 id=\"m2m-authentication-vs-m2m-authorization\" style=\"position:relative;\"><a href=\"#m2m-authentication-vs-m2m-authorization\" aria-label=\"m2m authentication vs m2m authorization permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>M2M Authentication vs M2M Authorization</h2>\n<p>Developers often mix up M2M authentication and M2M authorization, but they’re not the same. Here’s a simple way to remember the difference:</p>\n<ul>\n<li><strong>M2M authentication</strong> verifies <em>who</em> the machine is.</li>\n<li><strong>M2M authorization</strong> determines <em>what</em> that verified machine can do or access.</li>\n</ul>\n<p>Think of it like this:</p>\n<ul>\n<li>🔐 <strong>Authentication</strong> is like showing your ID to prove who you are.</li>\n<li>🛂 <strong>Authorization</strong> is like getting a backstage pass that defines where you can go and what you can do once you’re inside.</li>\n</ul>\n<p>For a deeper dive into these concepts, check out the article: <a href=\"https://supertokens.com/blog/authentication-vs-authorization\" target=\"_blank\" rel=\"nofollow\"><strong>Authentication vs Authorization: What’s the difference?</strong></a></p>\n<h2 id=\"-a-closer-look-at-how-m2m-authentication-works-\" style=\"position:relative;\"><a href=\"#-a-closer-look-at-how-m2m-authentication-works-\" aria-label=\" a closer look at how m2m authentication works  permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>✨ A Closer Look at How M2M Authentication Works ✨</h2>\n<h3 id=\"1-device-identification-and-authentication\" style=\"position:relative;\"><a href=\"#1-device-identification-and-authentication\" aria-label=\"1 device identification and authentication permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>1. Device Identification and Authentication</h3>\n<p>Devices authenticate themselves by presenting a unique Client ID and Secret to an OAuth 2.0 Authorization server. This process verifies the device’s identity before granting any permissions.</p>\n<h3 id=\"2-access-token-issuance\" style=\"position:relative;\"><a href=\"#2-access-token-issuance\" aria-label=\"2 access token issuance permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>2. Access Token Issuance</h3>\n<p>Upon successful authentication, the authorization server issues an Access Token. This token carries specific permissions that allow the device to perform authorized tasks or access designated resources.</p>\n<h3 id=\"3-secure-communication\" style=\"position:relative;\"><a href=\"#3-secure-communication\" aria-label=\"3 secure communication permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>3. Secure Communication</h3>\n<p>Only devices with valid tokens can initiate communication, ensuring that unauthorized entities are blocked. This strengthens data security by reducing the risk of malicious access.</p>\n<h3 id=\"4-communication-standards\" style=\"position:relative;\"><a href=\"#4-communication-standards\" aria-label=\"4 communication standards permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>4. Communication Standards</h3>\n<p>M2M systems often rely on protocols like MQTT, CoAP, and others to optimize data exchange for different use cases. These standards ensure efficient communication even in resource-constrained environments.</p>\n<h3 id=\"5-enhanced-security-and-efficiency\" style=\"position:relative;\"><a href=\"#5-enhanced-security-and-efficiency\" aria-label=\"5 enhanced security and efficiency permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>5. Enhanced Security and Efficiency</h3>\n<p>By enforcing strict authentication protocols, M2M communication prevents unauthorized access and ensures that data exchanges remain secure. This method is especially valuable in large-scale systems such as IoT networks and cloud infrastructures.</p>\n<h3 id=\"6-autonomous-operations\" style=\"position:relative;\"><a href=\"#6-autonomous-operations\" aria-label=\"6 autonomous operations permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>6. Autonomous Operations</h3>\n<p>M2M authentication enables devices to perform tasks independently, reducing the need for human oversight and improving operational efficiency in automated environments.</p>\n<h3 id=\"-step-by-step-the-client-credentials-grant-flow\" style=\"position:relative;\"><a href=\"#-step-by-step-the-client-credentials-grant-flow\" aria-label=\" step by step the client credentials grant flow permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>🚀 Step-by-Step: The Client Credentials Grant Flow</h3>\n<p>M2M authentication often uses the <a href=\"https://datatracker.ietf.org/doc/html/rfc6749#section-4.4\" target=\"_blank\" rel=\"nofollow\"><strong>Client Credentials Grant Flow</strong></a> in OAuth 2.0.</p>\n<p>The <strong>Client Credentials Grant Flow</strong> involves an application exchanging its application credentials, such as client ID and client secret, for an access token. This flow is ideal for M2M applications where the system needs to authenticate and authorize the application itself rather than a user.</p>\n<p>Here’s how it works:</p>\n<ol>\n<li>The <strong>Client</strong> authenticates with the <strong>Authorization Server</strong> by using its <strong>Client ID</strong> and <strong>Client Secret</strong>.</li>\n<li>The <strong>Authorization Server</strong> verifies the credentials.</li>\n<li>If valid, the <strong>Authorization Server</strong> issues an <strong>OAuth2 Access Token</strong>.</li>\n<li>The <strong>Client</strong> includes the <strong>Access Token</strong> in its requests to the <strong>Resource Server</strong>.</li>\n<li>The <strong>Resource Server</strong> verifies the Access Token.</li>\n<li>If the token is valid, the <strong>Resource Server</strong> grants access to the requested resource.</li>\n</ol>\n<p><span\n      class=\"gatsby-resp-image-wrapper\"\n      style=\"position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 630px; \"\n    >\n      <a\n    class=\"gatsby-resp-image-link\"\n    href=\"/static/93ba572b125cc850e47350607b529c7f/669eb/client-credentials-flow.png\"\n    style=\"display: block\"\n    target=\"_blank\"\n    rel=\"noopener\"\n  >\n    <span\n    class=\"gatsby-resp-image-background-image\"\n    style=\"padding-bottom: 77.84810126582278%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAQCAYAAAAWGF8bAAAACXBIWXMAAAsTAAALEwEAmpwYAAACPUlEQVQ4y3VT2W7cMAz0BzQxqcuypfWRpLsIijZNm6BPAfr/HzUsKFkb93ogLEv2cIYz6thb8Bhglgnm/iTu44xwniWeZ6SPJzndZyzbhHUZsGaHbTTYBpI1ENaBsAyEORByYJk8o/MhyKcvn8XEIBQDOA0wKcJqTQEhRXn7+SbzksUakmBZgiWY2w/y4/W7nB/uhPsbcZZhDEuXUsLzt2f4ENAzCRkWslqmrKec8PT1CfMyg4hgmEHUi7MWry8vuFwu6PsezCxEjM45h5xPcM7DGAvvfSlrHZiNOBfgfYC1Vn8qRURijME0TRiGoTRSQD3rFHWaHmBtlBgzzudHXC6PmOc7WDuI90mMcXJ7eyPKTMFa9f37e2lGJJ0ujCkySqc/qoCkdIdhyFemyq6x3NdHhlQ26wx+77zLQwgjct4K65xzGU8DbP/tgFIA9QPmeqgzVSb147JXAJ0bQWSKAY39zvAvQHFuEGMU1MowjEgpw9r6rsakdK9AhTlzm2FfRtXk74bVGY7jrA4Lsy3OEnEBilHBT6WBJkHftYmmQctarw1QqyagAE7TppLEuSgqrVYUlaqMY0zl6X1E/SbuqVgKaGOvTLtKt0qosehxqF0m7z+0c0Lf30iMM9b1Edt2RkpTkX91+Zivva57OniVddyr6168H4tpu+MFULyPotSNuRY0zCpzntcyRzWpnTXDUnqA3qQaenqXXA0xV+ubY9pVg1yvIeNwVta1iW3Bbgz5EIV/S/7PHo7XrmXxFxinibHUVUSHAAAAAElFTkSuQmCC'); background-size: cover; display: block;\"\n  ></span>\n  <img\n        class=\"gatsby-resp-image-image\"\n        alt=\"General Client Credentials Flow chart about how it works with two microservices as examples\"\n        title=\"General Client Credentials Flow chart about how it works with two microservices as examples\"\n        src=\"/static/93ba572b125cc850e47350607b529c7f/f058b/client-credentials-flow.png\"\n        srcset=\"/static/93ba572b125cc850e47350607b529c7f/c26ae/client-credentials-flow.png 158w,\n/static/93ba572b125cc850e47350607b529c7f/6bdcf/client-credentials-flow.png 315w,\n/static/93ba572b125cc850e47350607b529c7f/f058b/client-credentials-flow.png 630w,\n/static/93ba572b125cc850e47350607b529c7f/40601/client-credentials-flow.png 945w,\n/static/93ba572b125cc850e47350607b529c7f/669eb/client-credentials-flow.png 1244w\"\n        sizes=\"(max-width: 630px) 100vw, 630px\"\n        style=\"width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;\"\n        loading=\"lazy\"\n        decoding=\"async\"\n      />\n  </a>\n    </span></p>\n<p>This flow ensures secure, efficient authentication — keeping your data safe while allowing machines to communicate seamlessly.</p>\n<h2 id=\"why-is-machine-to-machine-authentication-important-️\" style=\"position:relative;\"><a href=\"#why-is-machine-to-machine-authentication-important-%EF%B8%8F\" aria-label=\"why is machine to machine authentication important ️ permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Why Is Machine-to-Machine Authentication Important? 🛡️</h2>\n<h3 id=\"1-prevents-unauthorized-access\" style=\"position:relative;\"><a href=\"#1-prevents-unauthorized-access\" aria-label=\"1 prevents unauthorized access permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>1. Prevents Unauthorized Access</h3>\n<p>By verifying machine identities, M2M authentication ensures that only trusted devices can connect and exchange data.</p>\n<h3 id=\"2-protect-sensitive-data\" style=\"position:relative;\"><a href=\"#2-protect-sensitive-data\" aria-label=\"2 protect sensitive data permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>2. Protect Sensitive Data</h3>\n<p>Strong authentication mechanisms prevent unverified machines from accessing confidential information, reducing the risk of data leaks.</p>\n<h3 id=\"3-enables-scalable-systems\" style=\"position:relative;\"><a href=\"#3-enables-scalable-systems\" aria-label=\"3 enables scalable systems permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>3. Enables Scalable Systems</h3>\n<p>M2M authentication simplifies security management in large networks, allowing new devices to authenticate securely without manual intervention.</p>\n<h3 id=\"4-ensures-compliance\" style=\"position:relative;\"><a href=\"#4-ensures-compliance\" aria-label=\"4 ensures compliance permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>4. Ensures Compliance</h3>\n<p>Implementing proper authentication protocols helps organizations meet security and privacy standards in industries like healthcare, finance, and IoT.</p>\n<h3 id=\"5-improves-operational-efficiency\" style=\"position:relative;\"><a href=\"#5-improves-operational-efficiency\" aria-label=\"5 improves operational efficiency permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>5. Improves Operational Efficiency</h3>\n<p>By automating the authentication process, M2M authentication minimizes human involvement, streamlining communication between services.</p>\n<h2 id=\"how-to-secure-your-machine-communication-with-supertokens\" style=\"position:relative;\"><a href=\"#how-to-secure-your-machine-communication-with-supertokens\" aria-label=\"how to secure your machine communication with supertokens permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>How to Secure Your Machine Communication With SuperTokens</h2>\n<p>SuperTokens recommends securing your machine-to-machine communication with <strong>OAuth2 specifications</strong>. You have to create an <strong>OAuth2 Provider</strong> and use the <strong>OAuth2 Client Credentials Flow</strong> for authorization.</p>\n<ol>\n<li><strong>Service A</strong> reaches out to the <strong>SuperTokens Backend SDK</strong> to get an <strong>OAuth Access Token</strong>.</li>\n<li>The <strong>SuperTokens Backend SDK</strong> responds back to <strong>Service A</strong> with an <strong>OAuth2 Access Token</strong>.</li>\n<li><strong>Service A</strong> then communicates with <strong>Service B</strong> by using the <strong>OAuth Access Token</strong>.</li>\n<li><strong>Service B</strong> talks to the <strong>SuperTokens Core Service</strong> to validate the <strong>OAuth Access Token</strong>.</li>\n<li>If the <strong>OAuth Access Token</strong> is valid, then <strong>Service B</strong> returns the requested resource.</li>\n</ol>\n<p><span\n      class=\"gatsby-resp-image-wrapper\"\n      style=\"position: relative; display: block; margin-left: auto; margin-right: auto; max-width: 630px; \"\n    >\n      <a\n    class=\"gatsby-resp-image-link\"\n    href=\"/static/90f51a925c3feb10561002a52ec1ca47/d48f1/machine-to-machine.png\"\n    style=\"display: block\"\n    target=\"_blank\"\n    rel=\"noopener\"\n  >\n    <span\n    class=\"gatsby-resp-image-background-image\"\n    style=\"padding-bottom: 92.40506329113923%; position: relative; bottom: 0; left: 0; background-image: url('data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAASCAYAAABb0P4QAAAACXBIWXMAAAsTAAALEwEAmpwYAAACsElEQVQ4y22Ty3ITMRBF/QOg93ukeZrY2E5iHFMYVlSlUqxZsOD/v+OKkuwBm2RxSj3t7us7rZ4FCzaLxkI2FqpioIOB9hraKQgtIZSAlBxSMJgKfYUWFIrTvGBaZuMUrL/gJJyT9Yxe4n7UeBg1dr3CtpOIhsFKBqduMZKBsSLIWTaaw2oBLRmCNzBaQAkKbwQ6L9B7gdYJdE7AKV6bNSeQ7H2NZxhjWDDGchFKweJhu8KXz0ecPh/w9LCBlrQK/4UTWMXRNg7ruwmfHncY2gbRm2pmFoQWDH0K+Li6w7pwt8TmbkKwFk4beHPGaY0UGkx9wo/n7/j96yce7zfoGjcL5hvBFAOGvkOKDfrUIIWI4Bo0lYhgS36qgh9XS9xv1/gw9uiif1tw6BL2+0dM04ShLQISWhAYSWEkgRGkjqHvWoxDj75L1UBw5kYwl4EGI9DGDm0ccL/9ihR8vQD7CgFnBKL3aJuuxk6L+VLyglKaBWfg5caUg9UB3nUouULZPckviDOCUygpoaSGKLctzrW0rA2lDJSyTCnJUtospc9KhUxZyRXof5xznMtKzbG5jqE6LHMk5H0VVMpnrWOe829RaoVQWSlX47m2nItLUWaMYJoOiHEF53ooJUHIOxTnlJJyXppJ/QxD6LFcHs+fpJSYRRezsvcO0/QBp9M37HYbDMMK0/QJZQRaRxSUarL3A1JK2G63OJ2+YhxHeO9fCzrnMI4DXl5esN/v0XVLpLSq8+VcosAYz9Y2aJqI4/GI5+dnDMOA0vuGQ1//7XA4YLPZIKV4efUma91Uh0LYvF5/w3K5w3q9wtPTse7smw6ttfVVuq5D27bVhVIGjIkrhyIrZRFjqjV939ee0vtKcIYQMsf477zE/34nhNz0VsGr9ZiT+SrG/HzFTe56vcra/AHHwssWJ2pF/AAAAABJRU5ErkJggg=='); background-size: cover; display: block;\"\n  ></span>\n  <img\n        class=\"gatsby-resp-image-image\"\n        alt=\"SuperTokens&#39; Client Credentials Flow Diagram Between Two Services - Service A and Service B\"\n        title=\"SuperTokens&#39; Client Credentials Flow Diagram Between Two Services - Service A and Service B\"\n        src=\"/static/90f51a925c3feb10561002a52ec1ca47/f058b/machine-to-machine.png\"\n        srcset=\"/static/90f51a925c3feb10561002a52ec1ca47/c26ae/machine-to-machine.png 158w,\n/static/90f51a925c3feb10561002a52ec1ca47/6bdcf/machine-to-machine.png 315w,\n/static/90f51a925c3feb10561002a52ec1ca47/f058b/machine-to-machine.png 630w,\n/static/90f51a925c3feb10561002a52ec1ca47/d48f1/machine-to-machine.png 796w\"\n        sizes=\"(max-width: 630px) 100vw, 630px\"\n        style=\"width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0;\"\n        loading=\"lazy\"\n        decoding=\"async\"\n      />\n  </a>\n    </span></p>\n<h2 id=\"steps-to-implementing-m2m-authentication-with-supertokens--super-simple-set-up\" style=\"position:relative;\"><a href=\"#steps-to-implementing-m2m-authentication-with-supertokens--super-simple-set-up\" aria-label=\"steps to implementing m2m authentication with supertokens  super simple set up permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Steps to Implementing M2M Authentication with SuperTokens — Super Simple Set Up</h2>\n<p>✅ SuperTokens makes OAuth2 setup straightforward with its dashboard and API.</p>\n<p>✅ Each service should have its own Client ID and Secret for secure authentication.</p>\n<p>✅ Tokens ensure services can only perform authorized tasks.</p>\n<p>✅ Token validation helps confirm the authenticity and permissions of each request.</p>\n<h3 id=\"-step-1-enable-oauth2-in-supertokens-dashboard\" style=\"position:relative;\"><a href=\"#-step-1-enable-oauth2-in-supertokens-dashboard\" aria-label=\" step 1 enable oauth2 in supertokens dashboard permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>🚀 Step 1: Enable OAuth2 in SuperTokens Dashboard</h3>\n<p>In the <strong>SuperTokens Dashboard</strong>, you need to enable the <strong>OAuth2 feature</strong>. This feature allows services (like APIs or background jobs) to authenticate securely without user involvement. Once enabled, you’ll see OAuth options in your application settings.</p>\n<ul>\n<li>Go to your <strong>SuperTokens.com Dashboard</strong>.</li>\n<li>Enable the <strong>OAuth2 feature</strong>.</li>\n<li>This unlocks OAuth recipes for your applications.</li>\n</ul>\n<h3 id=\"-step-2-create-oauth2-clients\" style=\"position:relative;\"><a href=\"#-step-2-create-oauth2-clients\" aria-label=\" step 2 create oauth2 clients permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>🔧 Step 2: Create OAuth2 Clients</h3>\n<p>Each service that needs authentication will need its own OAuth2 client. Think of this like giving each service its own ID badge.</p>\n<ul>\n<li>For each service (e.g., Task Service, Calendar Service), create a unique OAuth2 client.</li>\n<li>Use this code snippet to create a client:</li>\n</ul>\n<div\n              class=\"gatsby-code-button-container\"\n              data-toaster-id=\"11027236455590429000\"\n              data-toaster-class=\"gatsby-code-button-toaster\"\n              data-toaster-text-class=\"gatsby-code-button-toaster-text\"\n              data-toaster-text=\"Copied!\"\n              data-toaster-duration=\"3500\"\n              onClick=\"copyToClipboard(`const BASE_URL = '<CORE_API_ENDPOINT>';\nconst API_KEY = '<YOUR_API_KEY>';\n\nconst url = \\`\\${BASE_URL}/recipe/oauth/clients\\`;\nconst options = {\n  method: 'POST',\n  headers: {\n    'api-key': API_KEY,\n    'Content-Type': 'application/json; charset=utf-8',\n  },\n  body: JSON.stringify({\n    clientName: &quot;TaskService&quot;,\n    grantTypes: [&quot;client_credentials&quot;],\n    scope: &quot;event.create&quot;,\n    audience: [&quot;event&quot;],\n  })\n};\n\nfetch(url, options)\n  .then(response => response.json())\n  .then(json => console.log(json))\n  .catch(err => console.error(err));`, `11027236455590429000`)\"\n            >\n              <div\n                class=\"gatsby-code-button\"\n                data-tooltip=\"\"\n              >\n                <svg class=\"gatsby-code-button-icon\" xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\"><path fill=\"none\" d=\"M0 0h24v24H0V0z\"/><path d=\"M16 1H2v16h2V3h12V1zm-1 4l6 6v12H6V5h9zm-1 7h5.5L14 6.5V12z\"/></svg>\n              </div>\n            </div>\n<div class=\"gatsby-highlight\" data-language=\"javascript\"><pre class=\"language-javascript\"><code class=\"language-javascript\"><span class=\"token keyword\">const</span> <span class=\"token constant\">BASE_URL</span> <span class=\"token operator\">=</span> <span class=\"token string\">'&lt;CORE_API_ENDPOINT>'</span><span class=\"token punctuation\">;</span>\n<span class=\"token keyword\">const</span> <span class=\"token constant\">API_KEY</span> <span class=\"token operator\">=</span> <span class=\"token string\">'&lt;YOUR_API_KEY>'</span><span class=\"token punctuation\">;</span>\n\n<span class=\"token keyword\">const</span> url <span class=\"token operator\">=</span> <span class=\"token template-string\"><span class=\"token template-punctuation string\">`</span><span class=\"token interpolation\"><span class=\"token interpolation-punctuation punctuation\">${</span><span class=\"token constant\">BASE_URL</span><span class=\"token interpolation-punctuation punctuation\">}</span></span><span class=\"token string\">/recipe/oauth/clients</span><span class=\"token template-punctuation string\">`</span></span><span class=\"token punctuation\">;</span>\n<span class=\"token keyword\">const</span> options <span class=\"token operator\">=</span> <span class=\"token punctuation\">{</span>\n  <span class=\"token literal-property property\">method</span><span class=\"token operator\">:</span> <span class=\"token string\">'POST'</span><span class=\"token punctuation\">,</span>\n  <span class=\"token literal-property property\">headers</span><span class=\"token operator\">:</span> <span class=\"token punctuation\">{</span>\n    <span class=\"token string-property property\">'api-key'</span><span class=\"token operator\">:</span> <span class=\"token constant\">API_KEY</span><span class=\"token punctuation\">,</span>\n    <span class=\"token string-property property\">'Content-Type'</span><span class=\"token operator\">:</span> <span class=\"token string\">'application/json; charset=utf-8'</span><span class=\"token punctuation\">,</span>\n  <span class=\"token punctuation\">}</span><span class=\"token punctuation\">,</span>\n  <span class=\"token literal-property property\">body</span><span class=\"token operator\">:</span> <span class=\"token constant\">JSON</span><span class=\"token punctuation\">.</span><span class=\"token function\">stringify</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">{</span>\n    <span class=\"token literal-property property\">clientName</span><span class=\"token operator\">:</span> <span class=\"token string\">\"TaskService\"</span><span class=\"token punctuation\">,</span>\n    <span class=\"token literal-property property\">grantTypes</span><span class=\"token operator\">:</span> <span class=\"token punctuation\">[</span><span class=\"token string\">\"client_credentials\"</span><span class=\"token punctuation\">]</span><span class=\"token punctuation\">,</span>\n    <span class=\"token literal-property property\">scope</span><span class=\"token operator\">:</span> <span class=\"token string\">\"event.create\"</span><span class=\"token punctuation\">,</span>\n    <span class=\"token literal-property property\">audience</span><span class=\"token operator\">:</span> <span class=\"token punctuation\">[</span><span class=\"token string\">\"event\"</span><span class=\"token punctuation\">]</span><span class=\"token punctuation\">,</span>\n  <span class=\"token punctuation\">}</span><span class=\"token punctuation\">)</span>\n<span class=\"token punctuation\">}</span><span class=\"token punctuation\">;</span>\n\n<span class=\"token function\">fetch</span><span class=\"token punctuation\">(</span>url<span class=\"token punctuation\">,</span> options<span class=\"token punctuation\">)</span>\n  <span class=\"token punctuation\">.</span><span class=\"token function\">then</span><span class=\"token punctuation\">(</span><span class=\"token parameter\">response</span> <span class=\"token operator\">=></span> response<span class=\"token punctuation\">.</span><span class=\"token function\">json</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">)</span>\n  <span class=\"token punctuation\">.</span><span class=\"token function\">then</span><span class=\"token punctuation\">(</span><span class=\"token parameter\">json</span> <span class=\"token operator\">=></span> console<span class=\"token punctuation\">.</span><span class=\"token function\">log</span><span class=\"token punctuation\">(</span>json<span class=\"token punctuation\">)</span><span class=\"token punctuation\">)</span>\n  <span class=\"token punctuation\">.</span><span class=\"token function\">catch</span><span class=\"token punctuation\">(</span><span class=\"token parameter\">err</span> <span class=\"token operator\">=></span> console<span class=\"token punctuation\">.</span><span class=\"token function\">error</span><span class=\"token punctuation\">(</span>err<span class=\"token punctuation\">)</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span></code></pre></div>\n<p>✅ This registers your service so it can request access tokens later.</p>\n<p><strong>Key Details:</strong></p>\n<ul>\n<li><code class=\"language-text\">\"clientName\"</code> identifies the service (e.g., <code class=\"language-text\">TaskService</code>).</li>\n<li><code class=\"language-text\">\"grantTypes\": [\"client_credentials\"]</code> specifies that this client will authenticate using M2M.</li>\n<li><code class=\"language-text\">\"scope\"</code> defines the permissions this client will have.</li>\n</ul>\n<h3 id=\"️-step-3-single-app-vs-multi-app-setup\" style=\"position:relative;\"><a href=\"#%EF%B8%8F-step-3-single-app-vs-multi-app-setup\" aria-label=\"️ step 3 single app vs multi app setup permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>🏗️ Step 3: Single App vs Multi App Setup</h3>\n<p><strong>Single App Setup:</strong> For one project (e.g., a web app or API) that handles everything.<br>\n<strong>Multi App Setup:</strong> For larger projects where multiple services share one SuperTokens core.</p>\n<ul>\n<li><strong>Single App Example URL:</strong> <code class=\"language-text\">BASE_URL = \"&lt;CORE_API_ENDPOINT>\"</code></li>\n<li><strong>Multi App Example URL:</strong> <code class=\"language-text\">BASE_URL = \"&lt;CORE_API_ENDPOINT>/appid-task_service\"</code></li>\n</ul>\n<p><em>If you’re managing several services, the multi-app setup keeps things organized.</em></p>\n<h3 id=\"-step-4-set-up-the-authorization-service\" style=\"position:relative;\"><a href=\"#-step-4-set-up-the-authorization-service\" aria-label=\" step 4 set up the authorization service permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>🔐 Step 4: Set Up the Authorization Service</h3>\n<p>This is where you tell your app how to handle OAuth2 tokens.</p>\n<p><strong>Code Example:</strong></p>\n<div\n              class=\"gatsby-code-button-container\"\n              data-toaster-id=\"34146352431381090000\"\n              data-toaster-class=\"gatsby-code-button-toaster\"\n              data-toaster-text-class=\"gatsby-code-button-toaster-text\"\n              data-toaster-text=\"Copied!\"\n              data-toaster-duration=\"3500\"\n              onClick=\"copyToClipboard(`import supertokens from &quot;supertokens-node&quot;;\nimport OAuth2Provider from &quot;supertokens-node/recipe/oauth2provider&quot;;\n\nsupertokens.init({\n    supertokens: {\n        connectionURI: &quot;...&quot;,\n        apiKey: &quot;...&quot;,\n    },\n    appInfo: {\n        appName: &quot;...&quot;,\n        apiDomain: &quot;...&quot;,\n        websiteDomain: &quot;...&quot;,\n    },\n    recipeList: [\n      OAuth2Provider.init(),\n    ]\n});`, `34146352431381090000`)\"\n            >\n              <div\n                class=\"gatsby-code-button\"\n                data-tooltip=\"\"\n              >\n                <svg class=\"gatsby-code-button-icon\" xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\"><path fill=\"none\" d=\"M0 0h24v24H0V0z\"/><path d=\"M16 1H2v16h2V3h12V1zm-1 4l6 6v12H6V5h9zm-1 7h5.5L14 6.5V12z\"/></svg>\n              </div>\n            </div>\n<div class=\"gatsby-highlight\" data-language=\"javascript\"><pre class=\"language-javascript\"><code class=\"language-javascript\"><span class=\"token keyword\">import</span> supertokens <span class=\"token keyword\">from</span> <span class=\"token string\">\"supertokens-node\"</span><span class=\"token punctuation\">;</span>\n<span class=\"token keyword\">import</span> OAuth2Provider <span class=\"token keyword\">from</span> <span class=\"token string\">\"supertokens-node/recipe/oauth2provider\"</span><span class=\"token punctuation\">;</span>\n\nsupertokens<span class=\"token punctuation\">.</span><span class=\"token function\">init</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">{</span>\n    <span class=\"token literal-property property\">supertokens</span><span class=\"token operator\">:</span> <span class=\"token punctuation\">{</span>\n        <span class=\"token literal-property property\">connectionURI</span><span class=\"token operator\">:</span> <span class=\"token string\">\"...\"</span><span class=\"token punctuation\">,</span>\n        <span class=\"token literal-property property\">apiKey</span><span class=\"token operator\">:</span> <span class=\"token string\">\"...\"</span><span class=\"token punctuation\">,</span>\n    <span class=\"token punctuation\">}</span><span class=\"token punctuation\">,</span>\n    <span class=\"token literal-property property\">appInfo</span><span class=\"token operator\">:</span> <span class=\"token punctuation\">{</span>\n        <span class=\"token literal-property property\">appName</span><span class=\"token operator\">:</span> <span class=\"token string\">\"...\"</span><span class=\"token punctuation\">,</span>\n        <span class=\"token literal-property property\">apiDomain</span><span class=\"token operator\">:</span> <span class=\"token string\">\"...\"</span><span class=\"token punctuation\">,</span>\n        <span class=\"token literal-property property\">websiteDomain</span><span class=\"token operator\">:</span> <span class=\"token string\">\"...\"</span><span class=\"token punctuation\">,</span>\n    <span class=\"token punctuation\">}</span><span class=\"token punctuation\">,</span>\n    <span class=\"token literal-property property\">recipeList</span><span class=\"token operator\">:</span> <span class=\"token punctuation\">[</span>\n      OAuth2Provider<span class=\"token punctuation\">.</span><span class=\"token function\">init</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">,</span>\n    <span class=\"token punctuation\">]</span>\n<span class=\"token punctuation\">}</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span></code></pre></div>\n<p>This setup tells SuperTokens:</p>\n<ul>\n<li>Where to find your core server (connectionURI).</li>\n<li>The app’s name and domains.</li>\n<li>To include the OAuth2 provider.</li>\n</ul>\n<h3 id=\"-step-5-generate-access-tokens\" style=\"position:relative;\"><a href=\"#-step-5-generate-access-tokens\" aria-label=\" step 5 generate access tokens permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>🔄 Step 5: Generate Access Tokens</h3>\n<p>To generate a token, you send a POST request like this:</p>\n<div\n              class=\"gatsby-code-button-container\"\n              data-toaster-id=\"61548004613874310000\"\n              data-toaster-class=\"gatsby-code-button-toaster\"\n              data-toaster-text-class=\"gatsby-code-button-toaster-text\"\n              data-toaster-text=\"Copied!\"\n              data-toaster-duration=\"3500\"\n              onClick=\"copyToClipboard(`import fetch from &quot;node-fetch&quot;;\n\nconst response = await fetch(&quot;<YOUR_API_DOMAIN>/auth/oauth/token&quot;, {\n  method: &quot;POST&quot;,\n  headers: { &quot;Content-Type&quot;: &quot;application/json&quot; },\n  body: JSON.stringify({\n    clientId: &quot;<CLIENT_ID>&quot;,\n    clientSecret: &quot;<CLIENT_SECRET>&quot;,\n    grantType: &quot;client_credentials&quot;,\n    scope: [&quot;event.create&quot;],\n    audience: &quot;event&quot;\n  })\n});\n\nconst data = await response.json();\nconsole.log(data.accessToken);`, `61548004613874310000`)\"\n            >\n              <div\n                class=\"gatsby-code-button\"\n                data-tooltip=\"\"\n              >\n                <svg class=\"gatsby-code-button-icon\" xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\"><path fill=\"none\" d=\"M0 0h24v24H0V0z\"/><path d=\"M16 1H2v16h2V3h12V1zm-1 4l6 6v12H6V5h9zm-1 7h5.5L14 6.5V12z\"/></svg>\n              </div>\n            </div>\n<div class=\"gatsby-highlight\" data-language=\"javascript\"><pre class=\"language-javascript\"><code class=\"language-javascript\"><span class=\"token keyword\">import</span> fetch <span class=\"token keyword\">from</span> <span class=\"token string\">\"node-fetch\"</span><span class=\"token punctuation\">;</span>\n\n<span class=\"token keyword\">const</span> response <span class=\"token operator\">=</span> <span class=\"token keyword\">await</span> <span class=\"token function\">fetch</span><span class=\"token punctuation\">(</span><span class=\"token string\">\"&lt;YOUR_API_DOMAIN>/auth/oauth/token\"</span><span class=\"token punctuation\">,</span> <span class=\"token punctuation\">{</span>\n  <span class=\"token literal-property property\">method</span><span class=\"token operator\">:</span> <span class=\"token string\">\"POST\"</span><span class=\"token punctuation\">,</span>\n  <span class=\"token literal-property property\">headers</span><span class=\"token operator\">:</span> <span class=\"token punctuation\">{</span> <span class=\"token string-property property\">\"Content-Type\"</span><span class=\"token operator\">:</span> <span class=\"token string\">\"application/json\"</span> <span class=\"token punctuation\">}</span><span class=\"token punctuation\">,</span>\n  <span class=\"token literal-property property\">body</span><span class=\"token operator\">:</span> <span class=\"token constant\">JSON</span><span class=\"token punctuation\">.</span><span class=\"token function\">stringify</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">{</span>\n    <span class=\"token literal-property property\">clientId</span><span class=\"token operator\">:</span> <span class=\"token string\">\"&lt;CLIENT_ID>\"</span><span class=\"token punctuation\">,</span>\n    <span class=\"token literal-property property\">clientSecret</span><span class=\"token operator\">:</span> <span class=\"token string\">\"&lt;CLIENT_SECRET>\"</span><span class=\"token punctuation\">,</span>\n    <span class=\"token literal-property property\">grantType</span><span class=\"token operator\">:</span> <span class=\"token string\">\"client_credentials\"</span><span class=\"token punctuation\">,</span>\n    <span class=\"token literal-property property\">scope</span><span class=\"token operator\">:</span> <span class=\"token punctuation\">[</span><span class=\"token string\">\"event.create\"</span><span class=\"token punctuation\">]</span><span class=\"token punctuation\">,</span>\n    <span class=\"token literal-property property\">audience</span><span class=\"token operator\">:</span> <span class=\"token string\">\"event\"</span>\n  <span class=\"token punctuation\">}</span><span class=\"token punctuation\">)</span>\n<span class=\"token punctuation\">}</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n\n<span class=\"token keyword\">const</span> data <span class=\"token operator\">=</span> <span class=\"token keyword\">await</span> response<span class=\"token punctuation\">.</span><span class=\"token function\">json</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\nconsole<span class=\"token punctuation\">.</span><span class=\"token function\">log</span><span class=\"token punctuation\">(</span>data<span class=\"token punctuation\">.</span>accessToken<span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span></code></pre></div>\n<p><strong>Response Example:</strong></p>\n<div\n              class=\"gatsby-code-button-container\"\n              data-toaster-id=\"81502283847485690000\"\n              data-toaster-class=\"gatsby-code-button-toaster\"\n              data-toaster-text-class=\"gatsby-code-button-toaster-text\"\n              data-toaster-text=\"Copied!\"\n              data-toaster-duration=\"3500\"\n              onClick=\"copyToClipboard(`{\n  &quot;accessToken&quot;: &quot;<TOKEN_VALUE>&quot;,\n  &quot;expiresIn&quot;: 3600\n}`, `81502283847485690000`)\"\n            >\n              <div\n                class=\"gatsby-code-button\"\n                data-tooltip=\"\"\n              >\n                <svg class=\"gatsby-code-button-icon\" xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\"><path fill=\"none\" d=\"M0 0h24v24H0V0z\"/><path d=\"M16 1H2v16h2V3h12V1zm-1 4l6 6v12H6V5h9zm-1 7h5.5L14 6.5V12z\"/></svg>\n              </div>\n            </div>\n<div class=\"gatsby-highlight\" data-language=\"json\"><pre class=\"language-json\"><code class=\"language-json\"><span class=\"token punctuation\">{</span>\n  <span class=\"token property\">\"accessToken\"</span><span class=\"token operator\">:</span> <span class=\"token string\">\"&lt;TOKEN_VALUE>\"</span><span class=\"token punctuation\">,</span>\n  <span class=\"token property\">\"expiresIn\"</span><span class=\"token operator\">:</span> <span class=\"token number\">3600</span>\n<span class=\"token punctuation\">}</span></code></pre></div>\n<p><em>The token is valid for <strong>60 minutes</strong>. After that, you’ll need to request a new one.</em></p>\n<h3 id=\"-step-6-verify-an-access-token\" style=\"position:relative;\"><a href=\"#-step-6-verify-an-access-token\" aria-label=\" step 6 verify an access token permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>✅ Step 6: Verify an Access Token</h3>\n<p>To confirm a token is valid:\n<strong>Code Example Using <code class=\"language-text\">jose</code>:</strong></p>\n<div\n              class=\"gatsby-code-button-container\"\n              data-toaster-id=\"54663226323736125000\"\n              data-toaster-class=\"gatsby-code-button-toaster\"\n              data-toaster-text-class=\"gatsby-code-button-toaster-text\"\n              data-toaster-text=\"Copied!\"\n              data-toaster-duration=\"3500\"\n              onClick=\"copyToClipboard(`import jose from &quot;jose&quot;;\n\nconst JWKS = jose.createRemoteJWKSet(new URL('<YOUR_API_DOMAIN>/auth/jwt/jwks.json'))\n\nasync function validateClientCredentialsToken(jwt) {\n  const requiredScope = &quot;event.create&quot;;\n  const audience = &quot;event&quot;;\n\n  try {\n    const { payload } = await jose.jwtVerify(jwt, JWKS, {\n      audience,\n      requiredClaims: ['stt', 'scp'],\n    });\n\n    if (payload.stt !== 1) return false;\n    return payload.scp.includes(requiredScope);\n  } catch (err) {\n    return false;\n  }\n}`, `54663226323736125000`)\"\n            >\n              <div\n                class=\"gatsby-code-button\"\n                data-tooltip=\"\"\n              >\n                <svg class=\"gatsby-code-button-icon\" xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\"><path fill=\"none\" d=\"M0 0h24v24H0V0z\"/><path d=\"M16 1H2v16h2V3h12V1zm-1 4l6 6v12H6V5h9zm-1 7h5.5L14 6.5V12z\"/></svg>\n              </div>\n            </div>\n<div class=\"gatsby-highlight\" data-language=\"javascript\"><pre class=\"language-javascript\"><code class=\"language-javascript\"><span class=\"token keyword\">import</span> jose <span class=\"token keyword\">from</span> <span class=\"token string\">\"jose\"</span><span class=\"token punctuation\">;</span>\n\n<span class=\"token keyword\">const</span> <span class=\"token constant\">JWKS</span> <span class=\"token operator\">=</span> jose<span class=\"token punctuation\">.</span><span class=\"token function\">createRemoteJWKSet</span><span class=\"token punctuation\">(</span><span class=\"token keyword\">new</span> <span class=\"token class-name\">URL</span><span class=\"token punctuation\">(</span><span class=\"token string\">'&lt;YOUR_API_DOMAIN>/auth/jwt/jwks.json'</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">)</span>\n\n<span class=\"token keyword\">async</span> <span class=\"token keyword\">function</span> <span class=\"token function\">validateClientCredentialsToken</span><span class=\"token punctuation\">(</span><span class=\"token parameter\">jwt</span><span class=\"token punctuation\">)</span> <span class=\"token punctuation\">{</span>\n  <span class=\"token keyword\">const</span> requiredScope <span class=\"token operator\">=</span> <span class=\"token string\">\"event.create\"</span><span class=\"token punctuation\">;</span>\n  <span class=\"token keyword\">const</span> audience <span class=\"token operator\">=</span> <span class=\"token string\">\"event\"</span><span class=\"token punctuation\">;</span>\n\n  <span class=\"token keyword\">try</span> <span class=\"token punctuation\">{</span>\n    <span class=\"token keyword\">const</span> <span class=\"token punctuation\">{</span> payload <span class=\"token punctuation\">}</span> <span class=\"token operator\">=</span> <span class=\"token keyword\">await</span> jose<span class=\"token punctuation\">.</span><span class=\"token function\">jwtVerify</span><span class=\"token punctuation\">(</span>jwt<span class=\"token punctuation\">,</span> <span class=\"token constant\">JWKS</span><span class=\"token punctuation\">,</span> <span class=\"token punctuation\">{</span>\n      audience<span class=\"token punctuation\">,</span>\n      <span class=\"token literal-property property\">requiredClaims</span><span class=\"token operator\">:</span> <span class=\"token punctuation\">[</span><span class=\"token string\">'stt'</span><span class=\"token punctuation\">,</span> <span class=\"token string\">'scp'</span><span class=\"token punctuation\">]</span><span class=\"token punctuation\">,</span>\n    <span class=\"token punctuation\">}</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n\n    <span class=\"token keyword\">if</span> <span class=\"token punctuation\">(</span>payload<span class=\"token punctuation\">.</span>stt <span class=\"token operator\">!==</span> <span class=\"token number\">1</span><span class=\"token punctuation\">)</span> <span class=\"token keyword\">return</span> <span class=\"token boolean\">false</span><span class=\"token punctuation\">;</span>\n    <span class=\"token keyword\">return</span> payload<span class=\"token punctuation\">.</span>scp<span class=\"token punctuation\">.</span><span class=\"token function\">includes</span><span class=\"token punctuation\">(</span>requiredScope<span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n  <span class=\"token punctuation\">}</span> <span class=\"token keyword\">catch</span> <span class=\"token punctuation\">(</span>err<span class=\"token punctuation\">)</span> <span class=\"token punctuation\">{</span>\n    <span class=\"token keyword\">return</span> <span class=\"token boolean\">false</span><span class=\"token punctuation\">;</span>\n  <span class=\"token punctuation\">}</span>\n<span class=\"token punctuation\">}</span></code></pre></div>\n<p>This checks:</p>\n<ul>\n<li><strong>stt (SuperTokens Token Type)</strong> — Ensures it’s an OAuth2 token.</li>\n<li><strong>scp (Scope)</strong> — Confirms the token has the required permission.</li>\n</ul>\n<h3 id=\"-step-7-example-of-two-services-communicating-by-using-m2m\" style=\"position:relative;\"><a href=\"#-step-7-example-of-two-services-communicating-by-using-m2m\" aria-label=\" step 7 example of two services communicating by using m2m permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>🌍 Step 7: Example of Two Services Communicating By Using M2M</h3>\n<p>Imagine you have two services:</p>\n<ul>\n<li>Task Service — Creates tasks.</li>\n<li>Calendar Service — Manages events.</li>\n</ul>\n<p><strong>Flow:</strong></p>\n<ol>\n<li>Task Service requests a token from the Authorization Server.</li>\n<li>Using that token, Task Service makes a POST request to Calendar Service to create an event.</li>\n</ol>\n<h4 id=\"step-1-task-service-requests-token\" style=\"position:relative;\"><a href=\"#step-1-task-service-requests-token\" aria-label=\"step 1 task service requests token permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Step 1: Task Service Requests Token</h4>\n<div\n              class=\"gatsby-code-button-container\"\n              data-toaster-id=\"55701551856689660000\"\n              data-toaster-class=\"gatsby-code-button-toaster\"\n              data-toaster-text-class=\"gatsby-code-button-toaster-text\"\n              data-toaster-text=\"Copied!\"\n              data-toaster-duration=\"3500\"\n              onClick=\"copyToClipboard(`const tokenResponse = await fetch(&quot;<YOUR_API_DOMAIN>/auth/oauth/token&quot;, {\n  method: &quot;POST&quot;,\n  headers: { &quot;Content-Type&quot;: &quot;application/json&quot; },\n  body: JSON.stringify({\n    clientId: &quot;task_service&quot;,\n    clientSecret: &quot;super_secret_value&quot;,\n    grantType: &quot;client_credentials&quot;,\n    scope: [&quot;event.create&quot;],\n    audience: &quot;event&quot;\n  })\n});\n\nconst { accessToken } = await tokenResponse.json();`, `55701551856689660000`)\"\n            >\n              <div\n                class=\"gatsby-code-button\"\n                data-tooltip=\"\"\n              >\n                <svg class=\"gatsby-code-button-icon\" xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\"><path fill=\"none\" d=\"M0 0h24v24H0V0z\"/><path d=\"M16 1H2v16h2V3h12V1zm-1 4l6 6v12H6V5h9zm-1 7h5.5L14 6.5V12z\"/></svg>\n              </div>\n            </div>\n<div class=\"gatsby-highlight\" data-language=\"javascript\"><pre class=\"language-javascript\"><code class=\"language-javascript\"><span class=\"token keyword\">const</span> tokenResponse <span class=\"token operator\">=</span> <span class=\"token keyword\">await</span> <span class=\"token function\">fetch</span><span class=\"token punctuation\">(</span><span class=\"token string\">\"&lt;YOUR_API_DOMAIN>/auth/oauth/token\"</span><span class=\"token punctuation\">,</span> <span class=\"token punctuation\">{</span>\n  <span class=\"token literal-property property\">method</span><span class=\"token operator\">:</span> <span class=\"token string\">\"POST\"</span><span class=\"token punctuation\">,</span>\n  <span class=\"token literal-property property\">headers</span><span class=\"token operator\">:</span> <span class=\"token punctuation\">{</span> <span class=\"token string-property property\">\"Content-Type\"</span><span class=\"token operator\">:</span> <span class=\"token string\">\"application/json\"</span> <span class=\"token punctuation\">}</span><span class=\"token punctuation\">,</span>\n  <span class=\"token literal-property property\">body</span><span class=\"token operator\">:</span> <span class=\"token constant\">JSON</span><span class=\"token punctuation\">.</span><span class=\"token function\">stringify</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">{</span>\n    <span class=\"token literal-property property\">clientId</span><span class=\"token operator\">:</span> <span class=\"token string\">\"task_service\"</span><span class=\"token punctuation\">,</span>\n    <span class=\"token literal-property property\">clientSecret</span><span class=\"token operator\">:</span> <span class=\"token string\">\"super_secret_value\"</span><span class=\"token punctuation\">,</span>\n    <span class=\"token literal-property property\">grantType</span><span class=\"token operator\">:</span> <span class=\"token string\">\"client_credentials\"</span><span class=\"token punctuation\">,</span>\n    <span class=\"token literal-property property\">scope</span><span class=\"token operator\">:</span> <span class=\"token punctuation\">[</span><span class=\"token string\">\"event.create\"</span><span class=\"token punctuation\">]</span><span class=\"token punctuation\">,</span>\n    <span class=\"token literal-property property\">audience</span><span class=\"token operator\">:</span> <span class=\"token string\">\"event\"</span>\n  <span class=\"token punctuation\">}</span><span class=\"token punctuation\">)</span>\n<span class=\"token punctuation\">}</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n\n<span class=\"token keyword\">const</span> <span class=\"token punctuation\">{</span> accessToken <span class=\"token punctuation\">}</span> <span class=\"token operator\">=</span> <span class=\"token keyword\">await</span> tokenResponse<span class=\"token punctuation\">.</span><span class=\"token function\">json</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span></code></pre></div>\n<h4 id=\"step-2-task-service-sends-request-to-calendar-service\" style=\"position:relative;\"><a href=\"#step-2-task-service-sends-request-to-calendar-service\" aria-label=\"step 2 task service sends request to calendar service permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Step 2: Task Service Sends Request to Calendar Service</h4>\n<div\n              class=\"gatsby-code-button-container\"\n              data-toaster-id=\"91360818433666250000\"\n              data-toaster-class=\"gatsby-code-button-toaster\"\n              data-toaster-text-class=\"gatsby-code-button-toaster-text\"\n              data-toaster-text=\"Copied!\"\n              data-toaster-duration=\"3500\"\n              onClick=\"copyToClipboard(`await fetch(&quot;https://calendar.example.com/events&quot;, {\n  method: &quot;POST&quot;,\n  headers: {\n    &quot;Authorization&quot;: \\`Bearer \\${accessToken}\\`,\n    &quot;Content-Type&quot;: &quot;application/json&quot;\n  },\n  body: JSON.stringify({\n    title: &quot;Team Meeting&quot;,\n    date: &quot;2025-03-25&quot;,\n    location: &quot;Conference Room A&quot;\n  })\n});`, `91360818433666250000`)\"\n            >\n              <div\n                class=\"gatsby-code-button\"\n                data-tooltip=\"\"\n              >\n                <svg class=\"gatsby-code-button-icon\" xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\"><path fill=\"none\" d=\"M0 0h24v24H0V0z\"/><path d=\"M16 1H2v16h2V3h12V1zm-1 4l6 6v12H6V5h9zm-1 7h5.5L14 6.5V12z\"/></svg>\n              </div>\n            </div>\n<div class=\"gatsby-highlight\" data-language=\"javascript\"><pre class=\"language-javascript\"><code class=\"language-javascript\"><span class=\"token keyword\">await</span> <span class=\"token function\">fetch</span><span class=\"token punctuation\">(</span><span class=\"token string\">\"https://calendar.example.com/events\"</span><span class=\"token punctuation\">,</span> <span class=\"token punctuation\">{</span>\n  <span class=\"token literal-property property\">method</span><span class=\"token operator\">:</span> <span class=\"token string\">\"POST\"</span><span class=\"token punctuation\">,</span>\n  <span class=\"token literal-property property\">headers</span><span class=\"token operator\">:</span> <span class=\"token punctuation\">{</span>\n    <span class=\"token string-property property\">\"Authorization\"</span><span class=\"token operator\">:</span> <span class=\"token template-string\"><span class=\"token template-punctuation string\">`</span><span class=\"token string\">Bearer </span><span class=\"token interpolation\"><span class=\"token interpolation-punctuation punctuation\">${</span>accessToken<span class=\"token interpolation-punctuation punctuation\">}</span></span><span class=\"token template-punctuation string\">`</span></span><span class=\"token punctuation\">,</span>\n    <span class=\"token string-property property\">\"Content-Type\"</span><span class=\"token operator\">:</span> <span class=\"token string\">\"application/json\"</span>\n  <span class=\"token punctuation\">}</span><span class=\"token punctuation\">,</span>\n  <span class=\"token literal-property property\">body</span><span class=\"token operator\">:</span> <span class=\"token constant\">JSON</span><span class=\"token punctuation\">.</span><span class=\"token function\">stringify</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">{</span>\n    <span class=\"token literal-property property\">title</span><span class=\"token operator\">:</span> <span class=\"token string\">\"Team Meeting\"</span><span class=\"token punctuation\">,</span>\n    <span class=\"token literal-property property\">date</span><span class=\"token operator\">:</span> <span class=\"token string\">\"2025-03-25\"</span><span class=\"token punctuation\">,</span>\n    <span class=\"token literal-property property\">location</span><span class=\"token operator\">:</span> <span class=\"token string\">\"Conference Room A\"</span>\n  <span class=\"token punctuation\">}</span><span class=\"token punctuation\">)</span>\n<span class=\"token punctuation\">}</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span></code></pre></div>\n<h4 id=\"step-3-calendar-service-verifies-the-token\" style=\"position:relative;\"><a href=\"#step-3-calendar-service-verifies-the-token\" aria-label=\"step 3 calendar service verifies the token permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Step 3: Calendar Service Verifies the Token</h4>\n<div\n              class=\"gatsby-code-button-container\"\n              data-toaster-id=\"80581863652465300000\"\n              data-toaster-class=\"gatsby-code-button-toaster\"\n              data-toaster-text-class=\"gatsby-code-button-toaster-text\"\n              data-toaster-text=\"Copied!\"\n              data-toaster-duration=\"3500\"\n              onClick=\"copyToClipboard(`app.post('/events', async (req, res) => {\n  const token = req.headers['authorization']?.split('Bearer ')[1];\n\n  if (!token) return res.status(401).send(&quot;Unauthorized&quot;);\n\n  try {\n    const valid = await validateClientCredentialsToken(token);\n    if (!valid) return res.status(403).send(&quot;Forbidden&quot;);\n\n    // Token is valid — proceed with event creation\n    res.status(201).send({ message: &quot;Event created successfully!&quot; });\n  } catch {\n    res.status(403).send(&quot;Invalid token&quot;);\n  }\n});`, `80581863652465300000`)\"\n            >\n              <div\n                class=\"gatsby-code-button\"\n                data-tooltip=\"\"\n              >\n                <svg class=\"gatsby-code-button-icon\" xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\"><path fill=\"none\" d=\"M0 0h24v24H0V0z\"/><path d=\"M16 1H2v16h2V3h12V1zm-1 4l6 6v12H6V5h9zm-1 7h5.5L14 6.5V12z\"/></svg>\n              </div>\n            </div>\n<div class=\"gatsby-highlight\" data-language=\"javascript\"><pre class=\"language-javascript\"><code class=\"language-javascript\">app<span class=\"token punctuation\">.</span><span class=\"token function\">post</span><span class=\"token punctuation\">(</span><span class=\"token string\">'/events'</span><span class=\"token punctuation\">,</span> <span class=\"token keyword\">async</span> <span class=\"token punctuation\">(</span><span class=\"token parameter\">req<span class=\"token punctuation\">,</span> res</span><span class=\"token punctuation\">)</span> <span class=\"token operator\">=></span> <span class=\"token punctuation\">{</span>\n  <span class=\"token keyword\">const</span> token <span class=\"token operator\">=</span> req<span class=\"token punctuation\">.</span>headers<span class=\"token punctuation\">[</span><span class=\"token string\">'authorization'</span><span class=\"token punctuation\">]</span><span class=\"token operator\">?.</span><span class=\"token function\">split</span><span class=\"token punctuation\">(</span><span class=\"token string\">'Bearer '</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">[</span><span class=\"token number\">1</span><span class=\"token punctuation\">]</span><span class=\"token punctuation\">;</span>\n\n  <span class=\"token keyword\">if</span> <span class=\"token punctuation\">(</span><span class=\"token operator\">!</span>token<span class=\"token punctuation\">)</span> <span class=\"token keyword\">return</span> res<span class=\"token punctuation\">.</span><span class=\"token function\">status</span><span class=\"token punctuation\">(</span><span class=\"token number\">401</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">.</span><span class=\"token function\">send</span><span class=\"token punctuation\">(</span><span class=\"token string\">\"Unauthorized\"</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n\n  <span class=\"token keyword\">try</span> <span class=\"token punctuation\">{</span>\n    <span class=\"token keyword\">const</span> valid <span class=\"token operator\">=</span> <span class=\"token keyword\">await</span> <span class=\"token function\">validateClientCredentialsToken</span><span class=\"token punctuation\">(</span>token<span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n    <span class=\"token keyword\">if</span> <span class=\"token punctuation\">(</span><span class=\"token operator\">!</span>valid<span class=\"token punctuation\">)</span> <span class=\"token keyword\">return</span> res<span class=\"token punctuation\">.</span><span class=\"token function\">status</span><span class=\"token punctuation\">(</span><span class=\"token number\">403</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">.</span><span class=\"token function\">send</span><span class=\"token punctuation\">(</span><span class=\"token string\">\"Forbidden\"</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n\n    <span class=\"token comment\">// Token is valid — proceed with event creation</span>\n    res<span class=\"token punctuation\">.</span><span class=\"token function\">status</span><span class=\"token punctuation\">(</span><span class=\"token number\">201</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">.</span><span class=\"token function\">send</span><span class=\"token punctuation\">(</span><span class=\"token punctuation\">{</span> <span class=\"token literal-property property\">message</span><span class=\"token operator\">:</span> <span class=\"token string\">\"Event created successfully!\"</span> <span class=\"token punctuation\">}</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n  <span class=\"token punctuation\">}</span> <span class=\"token keyword\">catch</span> <span class=\"token punctuation\">{</span>\n    res<span class=\"token punctuation\">.</span><span class=\"token function\">status</span><span class=\"token punctuation\">(</span><span class=\"token number\">403</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">.</span><span class=\"token function\">send</span><span class=\"token punctuation\">(</span><span class=\"token string\">\"Invalid token\"</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span>\n  <span class=\"token punctuation\">}</span>\n<span class=\"token punctuation\">}</span><span class=\"token punctuation\">)</span><span class=\"token punctuation\">;</span></code></pre></div>\n<h2 id=\"conclusion\" style=\"position:relative;\"><a href=\"#conclusion\" aria-label=\"conclusion permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>Conclusion</h2>\n<p><strong>Machine-to-machine (M2M) authentication</strong> is a way for services to communicate securely, without human involvement. Instead of a person logging in, one service presents a token or key to prove its identity to another service.</p>\n<p>M2M authentication is especially important for:</p>\n<ul>\n<li>✅ <strong>Microservices</strong> that need to share data securely.</li>\n<li>✅ <strong>Automated systems</strong> like order processing, data syncing, or scheduled tasks.</li>\n<li>✅ <strong>API integrations</strong> that connect external services safely.</li>\n</ul>\n<p>By implementing M2M authentication, you ensure that your services can trust one another, thereby reducing the risk of unauthorized access and improving overall system security.</p>\n<p>Whether you’re working with microservices, internal APIs, or third-party integrations, this method offers a solid, lightweight solution for secure communication.</p>","frontmatter":{"date":"March 18, 2025","title":"Understanding Machine-to-Machine (M2M) Authentication: 2025 Guide","cover":"M2M.png","author":"Maria Shimkovska","description":"Explore the essentials of machine-to-machine authentication and best practices for implementing secure M2M communication."},"fields":{"slug":"/machine-to-machine-authentication/"}},"site":{"siteMetadata":{"title":"SuperTokens Blog"}}},"pageContext":{"id":"771e1146-9cac-5500-9080-02c78ef2e33c","fields__slug":"/machine-to-machine-authentication/","__params":{"fields__slug":"machine-to-machine-authentication"}}},
    "staticQueryHashes": []}