For a Prometheus scrape protected by OAuth2, Prometheus—not the Spring Boot application—uses the client_credentials grant to obtain an access token and sends it to the metrics endpoint. Spring Boot must accept and validate that bearer token, typically through Spring Security’s OAuth2 Resource Server support. Spring Security’s OAuth2 Client is for the reverse direction: when the application makes its own authenticated requests to another service.
How the scrape authentication flow works
- Prometheus contacts the authorization server’s token endpoint using its client credentials and any required scope.
- The authorization server returns an access token for the Prometheus client.
- Prometheus sends the token as a bearer token when requesting the metrics endpoint.
- Spring Security validates the token and applies the application’s authorization rules to that endpoint.
Prometheus supports OAuth2 in its scrape HTTP configuration. Its documented oauth2 fields include client_id, token_url, optional client_secret or client_secret_file, grant_type, scopes, optional endpoint_params, and TLS settings for token requests. The grant type defaults to client_credentials. Consult the Prometheus HTTP configuration reference for the configuration syntax supported by the Prometheus version you deploy.
Provide the actual token URL, client identity, secret, and scope issued for your environment; there is no universal set of values that can be filled in safely without knowing your identity provider. Keep credentials in your deployment’s secret-management mechanism. Prometheus documents that OAuth2 cannot be used alongside basic_auth or authorization in the same HTTP configuration.
Configure Spring Boot to protect the metrics endpoint
The application is the resource server in this flow. Spring Security’s OAuth2 Resource Server support is designed to accept bearer tokens on inbound requests. For JWTs, the reference describes validation through a JwtDecoder; for opaque tokens, it describes validation through an OpaqueTokenIntrospector. Choose the validation mode that matches the token format and identity-provider setup.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems#1 Best Overall
After token validation, configure authorization for the metrics route according to your policy and the token’s claims or scopes. The route itself, Actuator exposure settings, required authority, and identity-provider-specific validation details vary by application. Do not assume that a particular metrics path or authority applies to every Spring Boot deployment. See the Spring Security OAuth2 Resource Server reference for the supported resource-server patterns.
Keep OAuth2 Client separate from scrape authentication
Spring Security’s OAuth2 Client is appropriate when the Spring application makes an outbound request to a protected API and needs to obtain or attach an access token. Its documented approach uses an OAuth2AuthorizedClientManager with HTTP-client integration. That is separate from Prometheus obtaining a token to call the Spring application.
Rank #2
With the client-credentials grant, the token represents the client application, not an end user. In a web application that also supports user login, review principal resolution: Spring’s documented default can associate an authorized client with the current user principal. The Spring Security OAuth2 Client reference covers outbound client configuration.
Choose the right component for each responsibility
| Concern | Component and role | When to use it |
|---|---|---|
| Get a token for a Prometheus scrape | Prometheus OAuth2 scrape configuration | Prometheus calls the authorization server and includes the token with its scrape request. |
| Validate a token on the metrics endpoint | Spring Security OAuth2 Resource Server | Spring Boot receives the bearer token and validates it as a JWT or opaque token. |
| Get a token for an application’s outbound API call | Spring Security OAuth2 Client | The Spring application itself calls a protected remote service. |
The choice follows request direction: the HTTP caller obtains the token, while the receiving protected resource validates and authorizes it. The authorization server, token format, audience, scope, endpoint, and application policy determine the actual configuration.
Rank #3
Verify the complete deployment path
- Confirm Prometheus can reach both the token endpoint and the metrics endpoint.
- Check that the authorization server issues a token with the audience and scope expected by the application.
- Confirm Spring Security validates the token using the correct JWT or opaque-token mechanism.
- Check that the authenticated token has the authority required to access the metrics route.
- Review Prometheus and application logs for failures at token acquisition, token validation, and endpoint authorization; these are separate stages and can fail independently.
Prometheus configuration and Spring Security APIs can change. The documentation pages cited here were consulted on October 4, 2026; check the references for the Prometheus, Spring Boot, and Spring Security versions used in your deployment.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




