Resta saysClient Credentials and Device Code flows cover machine and input-limited clients.
Not every flow involves a user. The Client Credentials flow authenticates a machine/service directly (its own id + secret → token) for server-to-server APIs. The Device Code flow handles TVs and CLIs with no browser/keyboard: the device shows a code, you approve it on your phone. Pick the flow that matches the client's capabilities.
Power-ups you unlock
Client Credentials: service-to-service (no user)
Device Code: TVs, CLIs, limited input
Each flow fits a client type
Choose by what the client can do
The 401 Bandit attacks — common mistakes
Using Client Credentials for user-specific data
Forcing a browser flow on a TV/CLI
Mismatching flow to client capabilities
Boss battleMatch each flow to: a cron job, a smart TV, a web app with login.
Example code
<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>cron job → Client Credentials
smart TV → Device Code
web app → Authorization Code (+PKCE)</pre></body></html>