# Support client\_credential and password grants in OAuth2

**URL:** <https://forum.mautic.org/t/support-client-credential-and-password-grants-in-oauth2/13849>\
**Category:** Ideas and Feature Requests\
**Created:** [April 10, 2020, 1:53pm UTC](https://forum.mautic.org/t/support-client-credential-and-password-grants-in-oauth2/13849 "2020-04-10T13:53:51Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![dennisameling](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/dennisameling/32/958_2.png) [@dennisameling](https://forum.mautic.org/u/dennisameling)\
**Post date:** [April 10, 2020, 1:53pm UTC](https://forum.mautic.org/t/support-client-credential-and-password-grants-in-oauth2/13849/1 "2020-04-10T13:53:51Z")

</div>

**My idea is:**

Currently, Mautic [only supports](https://developer.mautic.org/#oauth-2) the the `authorization_code` and `refresh_token` grant types for OAuth2 authentication against the REST API.

Please add support for the `client_credential` and `password` grants in OAuth2 to:

1. Make authentication easier for people who want to use the REST API
2. Allow the Mautic contributors to deprecate support for OAuth1a (which is [a fork that’s currently maintained by Mautic contributors](https://github.com/mautic/BazingaOAuthServerBundle)) and focus development efforts on OAuth2

**I think these groups of people would benefit from this idea:**  
People who want to use Mautic’s REST API and Mautic core contributors (less maintenance)

**Why I think they would benefit from this idea:**  
See above

**Any code or resources to support this idea:**  
Not yet (TBD)

**Are you willing to work on this idea?:**  
Yes, if time allows

**What skills and resources do you need to explore this further?**  
A better understanding of the OAuth2 library that’s currently used by Mautic (friendsofsymfony/oauth-server-bundle [if I’m not mistaken](https://github.com/mautic/mautic/blob/9ddffa6b25cdd56413face9ed07d380cc49b62aa/composer.json)?)

---

<div class="post-metadata">

**Author:** ![a.bell](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/a.bell/32/2264_2.png) [@a.bell](https://forum.mautic.org/u/a.bell)\
**Post date:** [April 21, 2020, 3:34pm UTC](https://forum.mautic.org/t/support-client-credential-and-password-grants-in-oauth2/13849/2 "2020-04-21T15:34:53Z")

</div>

It would be great to provide a way which would allow mautic api authentication without prompting a user to login.

Am I correct in understanding that this is currently not possible?

---

<div class="post-metadata">

**Author:** ![dennisameling](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/dennisameling/32/958_2.png) [@dennisameling](https://forum.mautic.org/u/dennisameling)\
**Post date:** [April 22, 2020, 7:38am UTC](https://forum.mautic.org/t/support-client-credential-and-password-grants-in-oauth2/13849/3 "2020-04-22T07:38:53Z")

</div>

@a.bell It is currently possible to connect to Mautic’s REST API without a user having to log in by using Basic Auth: [https://developer.mautic.org/#basic-authentication](https://developer.mautic.org/#basic-authentication)

It might not be ideal, but at least should be a feasible workaround for now 🙂
