Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
World desk3 min

OAuth2 Client Credentials for Prometheus Scrapes in Spring Boot

Prometheus obtains the scrape token; Spring Boot protects the metrics endpoint as an OAuth2 resource server. Learn how the roles fit together and what to verify.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a Prometheus scrape protected by OAuth2, Prometheus—not the Spring Boot application—uses the client_credentials grant to obtain an access token and sends it to the metrics endpoint. Spring Boot must accept and validate that bearer token, typically through Spring Security’s OAuth2 Resource Server support. Spring Security’s OAuth2 Client is for the reverse direction: when the application makes its own authenticated requests to another service.

How the scrape authentication flow works

  1. Prometheus contacts the authorization server’s token endpoint using its client credentials and any required scope.
  2. The authorization server returns an access token for the Prometheus client.
  3. Prometheus sends the token as a bearer token when requesting the metrics endpoint.
  4. Spring Security validates the token and applies the application’s authorization rules to that endpoint.

Prometheus supports OAuth2 in its scrape HTTP configuration. Its documented oauth2 fields include client_id, token_url, optional client_secret or client_secret_file, grant_type, scopes, optional endpoint_params, and TLS settings for token requests. The grant type defaults to client_credentials. Consult the Prometheus HTTP configuration reference for the configuration syntax supported by the Prometheus version you deploy.

Provide the actual token URL, client identity, secret, and scope issued for your environment; there is no universal set of values that can be filled in safely without knowing your identity provider. Keep credentials in your deployment’s secret-management mechanism. Prometheus documents that OAuth2 cannot be used alongside basic_auth or authorization in the same HTTP configuration.

Configure Spring Boot to protect the metrics endpoint

The application is the resource server in this flow. Spring Security’s OAuth2 Resource Server support is designed to accept bearer tokens on inbound requests. For JWTs, the reference describes validation through a JwtDecoder; for opaque tokens, it describes validation through an OpaqueTokenIntrospector. Choose the validation mode that matches the token format and identity-provider setup.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

After token validation, configure authorization for the metrics route according to your policy and the token’s claims or scopes. The route itself, Actuator exposure settings, required authority, and identity-provider-specific validation details vary by application. Do not assume that a particular metrics path or authority applies to every Spring Boot deployment. See the Spring Security OAuth2 Resource Server reference for the supported resource-server patterns.

Keep OAuth2 Client separate from scrape authentication

Spring Security’s OAuth2 Client is appropriate when the Spring application makes an outbound request to a protected API and needs to obtain or attach an access token. Its documented approach uses an OAuth2AuthorizedClientManager with HTTP-client integration. That is separate from Prometheus obtaining a token to call the Spring application.

With the client-credentials grant, the token represents the client application, not an end user. In a web application that also supports user login, review principal resolution: Spring’s documented default can associate an authorized client with the current user principal. The Spring Security OAuth2 Client reference covers outbound client configuration.

Choose the right component for each responsibility

Concern Component and role When to use it
Get a token for a Prometheus scrape Prometheus OAuth2 scrape configuration Prometheus calls the authorization server and includes the token with its scrape request.
Validate a token on the metrics endpoint Spring Security OAuth2 Resource Server Spring Boot receives the bearer token and validates it as a JWT or opaque token.
Get a token for an application’s outbound API call Spring Security OAuth2 Client The Spring application itself calls a protected remote service.

The choice follows request direction: the HTTP caller obtains the token, while the receiving protected resource validates and authorizes it. The authorization server, token format, audience, scope, endpoint, and application policy determine the actual configuration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Verify the complete deployment path

  • Confirm Prometheus can reach both the token endpoint and the metrics endpoint.
  • Check that the authorization server issues a token with the audience and scope expected by the application.
  • Confirm Spring Security validates the token using the correct JWT or opaque-token mechanism.
  • Check that the authenticated token has the authority required to access the metrics route.
  • Review Prometheus and application logs for failures at token acquisition, token validation, and endpoint authorization; these are separate stages and can fail independently.

Prometheus configuration and Spring Security APIs can change. The documentation pages cited here were consulted on October 4, 2026; check the references for the Prometheus, Spring Boot, and Spring Security versions used in your deployment.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.