---
category: [Administration & Integrations, Platform and Product Extensions, Platform and Product Extensions/Integration, Administration & Integrations/Custom Integrations & Apps, Platform and Product Extensions/Workday Extend]
keyword: [Extend, Presentation Components, Endpoint authentication, UI components]
nav: wcp_docs
parent_url: /wcp_docs/
title: >- 
  Reference: OAuth2 Client Credentials
layout: subsection
---

<a id="section_oauth2_client_creds"></a>
Use the `OAUTH_CLIENT_CREDENTIAL` authentication scheme for third-party REST API endpoints that implement the OAuth2 client credentials grant type.

Presentation Components invoke the token endpoint from the third-party REST service with the stored client credentials. Upon successful authentication, Presentation Components receive an access token from the third-party token endpoint. Presentation Components store the access token in the user session. Subsequent calls to third-party endpoints using `OAUTH_CLIENT_CREDENTIAL` send the access token in the request header.

To use the `OAUTH_CLIENT_CREDENTIAL` authentication scheme, you must:

-   Register your custom app with the third-party REST service provider to get an OAuth2 client ID and client secret. Use the client ID as the `id` and `referenceId` in the `authType` definition in the SMD.
-   Store the client credentials in the Workday credential store using the <b>Create External Client CredStore</b> task on Workday.


## <a id="section_zl5_blx_sfb"></a>SMD authType Attributes

<table><thead><tr><th>Attribute</th><th>Value</th></tr></thead><tbody><tr><td>id</td><td>A unique ID. Use this <code>id</code> in your PMDs to reference this authentication scheme. <p>Optionally, you can set this value to the <code>referenceId</code>, which is the <b>External Reference Id</b> on the External Client CredStore.</p></td></tr><tr><td>referenceId</td><td>Set this value to the External Reference Id you defined for your app on the <b>Create External Client CredStore</b> task on Workday.</td></tr><tr><td>scheme</td><td><code>OAUTH_CLIENT_CREDENTIAL</code> (case-sensitive)</td></tr><tr><td>source</td><td>Specify <code>CREDSTORE</code>, which indicates that the client credentials are stored in the Workday credential store.</td></tr><tr><td>providerType</td><td>Specifies how to send the request. Default is <code>BASIC_AUTH</code>. Valid values: <ul><li><code>STANDARD_POST</code> - Uses HTTP POST method to send the authentication request.
</li><li><code>BASIC_AUTH</code> - Uses the <b>Authorization</b> request header whose value is <code>Basic base64-encoded({client_id}:{client_secret})</code>.
</li></ul></td></tr></tbody></table><br/>

## <a id="section_xvp_clx_sfb"></a>Example

```
  "siteAuth" : {
    "authTypes" : [ 
      {
       "id": "OCTanner",
       "descriptor": "OCTanner Client Credential Auth type",
       "source": "CREDSTORE",      
       "scheme": "OAUTH_CLIENT_CREDENTIAL",
       "providerType": "STANDARD_POST",
       "referenceId": "OCTanner"
      },
      {
        "id" : "sso",
        "scheme" : "SSO"
      }
    ]
  }
```

<b>Note:</b> The default authentication type is always `SSO`. To override `SSO` with the `OAUTH_CLIENT_CREDENTIAL` authentication type, specify its `id` in the `authType` attribute of the endpoint in the PMD.

### Related Information

[Declare Authentication Types in the SMD](/wcp_docs/nyw1530545468565.html)

[Define Endpoint Authentication in the PMD](/wcp_docs/yea1530546235609.html)

[Reference: Tenant Redirect URLs for External OAuth Providers](/wcp_docs/cpx1566499453357.html)

