Controlling API Access With the Client Credentials Grant in FusionAuth

Опубликовано: 20 Май 2026
на канале: FusionAuth
3,693
19

This video explains how the client credentials grant works, how to use FusionAuth's entity management to control API access, and how JWT-based permissions let you securely manage service-to-service communication.

📌 Get Started with FusionAuth for free: https://fusionauth.io/docs/get-started
📌 Example Client Credentials Grant: https://fusionauth.io/docs/lifecycle/...

Timestamps:

00:00 – Introduction to Client Credentials Grant
00:17 – License Key Requirements
00:42 – What Are Entities and Entity Types?
01:41 – Setting Up API Entity Types with Permissions
02:57 – Creating Example API Entities (To-Do, Reminder, Email)
04:14 – Defining Grants Between Internal APIs
05:13 – How the Client Credentials Grant Works in FusionAuth
06:20 – Requesting a JWT for Service Authentication
07:26 – Passing the Token to Target APIs
08:19 – Common Permission Mismatch Debugging
09:02 – Viewing and Decoding the JWT
10:45 – Audience, Scopes, and Subject Validation
11:40 – Permission Checks at the API Layer
12:12 – Example: Denied Request Without Proper Scope
12:48 – Benefits of Centralized Permission Management

🔔 Subscribe for more authentication and API security walkthroughs.