---
title: Form parameters (HTTP POST)
description: Authenticate OAuth 2.0 clients by sending client_id and client_secret form parameters in HTTP POST requests
component: pingam
version: 8
page_id: pingam:am-oauth2:client-auth-form
canonical_url: https://docs.pingidentity.com/pingam/8.1/am-oauth2/client-auth-form.html
llms_txt: https://docs.pingidentity.com/pingam/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
revdate: 2026-06-01T14:34:20Z
keywords: ["Authentication", "OAuth 2.0", "Federation", "HTTP", "Clients"]
page_aliases: ["oauth2-guide:client-auth-form.adoc"]
superseded_by: https://docs.pingidentity.com/pingam/8.1/am-oauth2/client-auth-form.html
---

# Form parameters (HTTP POST)

The OAuth 2.0 client authenticates by sending `client_id` and `client_secret` form parameters in an HTTP POST request:

```bash
$ curl \
--request POST \
--data "client_id=myClient" \
--data "client_secret=mySecret" \
…​
```

To use this authentication method for a confidential OAuth 2.0 client, edit the client profile in the AM admin UI:

1. Go to Realms > *realm name* > Applications > OAuth 2.0 > Clients > *client ID* > Advanced.

2. Set the Token Endpoint Authentication Method to `client_secret_post` and save your work.

Make sure all connections to AM use HTTPS to protect the secret.
