App-only OAuth 2.0 flow in which the application signs in as itself, not on behalf of a user; daemons, service-to-service calls and managed identities rely on it.
Also called grant.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Client credentials in context, with comparison tables and the common traps.
Terms in this definition
- OAuth 2.0
Standard authorisation protocol through which the Microsoft identity platform hands apps access tokens. In the client credentials flow, an app exchanges its client ID and client secret for a token.
- Flow
The unit of work inside a Lakeflow pipeline that takes data from a source, transforms it and lands it in a destination like a streaming table. Streaming flows either append or update, and
CREATE FLOWlets you declare a flow apart from the table it feeds. - Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
Related terms
- App roles
Roles declared by an API in its app registration. When one app calls another using client credentials, the assigned roles appear in the token's
rolesclaim. - Daemon app
Service or background process that runs without anyone signed in, authenticating as itself via client credentials, which is why it needs application permissions with admin consent.
- M2M
Lets automation call Azure Databricks by having a service principal swap its OAuth client ID and secret for short-lived access tokens, known as the client credentials flow; this machine-to-machine approach is the preferred one for unattended processes.