
j56jp (j56jp) asked a question.
Hi,
I have a use-case where a user needs to authenticate with Okta, but the software that requests and uses the auth token resides on their personal machine. I have read through a very helpful OAuth guide (https://www.oauth.com/oauth2-servers/background), but did not find a flow that best fit my use-case. I thought we could use the Resource Owner Password flow (https://developer.okta.com/authentication-guide/implementing-authentication/password), but we don't want to store the client secret on their machine.
What is a good solution for this? Someone suggested we create a separate Okta app just for this user (a private app so to speak).

My name is Tomas and I'll be assisting you with this case.
The private app for the users seems like the best way to proceed on this issue, unfortunately I cannot assist you with a clear documentation that has the steps for the configuration as well.
Please open a ticket with Okta Support for further assistance in regards to this matter.