---
editLink: false
lastUpdated: false
---

[@salesforce/b2c-tooling-sdk](../../modules.md) / [auth](../index.md) / ClientAuthMethod

# Type Alias: ClientAuthMethod

> **ClientAuthMethod** = `"basic"` \| `"basic-unencoded"` \| `"body"`

Defined in: [packages/b2c-tooling-sdk/src/auth/client-credentials.ts:75](https://github.com/SalesforceCommerceCloud/b2c-developer-tooling/blob/bceb8da43dd8bc63d57932bbd905d36a1b40c949/packages/b2c-tooling-sdk/src/auth/client-credentials.ts#L75)

How OAuth client credentials are sent to the token endpoint.

- `basic`: `Authorization: Basic` header with each component form-url-encoded
  per RFC 6749 §2.3.1 (`client_secret_basic`). The default.
- `basic-unencoded`: `Authorization: Basic` header over the raw `id:secret`,
  without per-component encoding. For proxies and brokers that substitute a
  literal value into the decoded header. A secret containing `+` or `%` is
  misread by Account Manager in this mode.
- `body`: `client_id` and `client_secret` in the form-url-encoded request body
  (`client_secret_post`).
