O auth2 client credentials (oauth2)
Azure AD B2C OAuth2 client credentials, used by organisations of type Partner. Penfold provisions an app registration per organisation (client ID and client secret). Your servers obtain access tokens from the token endpoint and send them as Bearer tokens; there is no interactive sign-in.
Organisations of type Payroll instead use the OAuth2 Authorization Code flow with PKCE — see Authentication in the API description above.
| Flow type | clientCredentials |
|---|---|
| Token URL | https://login.microsoftonline.com/36d1ec63-a7dc-48ca-a634-5514be9a63dd/oauth2/v2.0/token |
| Scopes |
|