clientCredentials
fun TokenProvider.Companion.clientCredentials(clientId: String, clientSecret: String, apiHost: String, engine: HttpEngine = OkHttpEngine()): TokenProvider
Exchange client credentials for an access token, with caching.
Correct on a server; wrong on a device. The clientSecret is long-lived and org-scoped: anyone who extracts it can mint tokens as that org until it is rotated, and rotating means redeploying every consumer. An APK is a zip file, so shipping this in one publishes the secret.
On Android, and in any untrusted client, have a service you control perform this exchange and use caching over a call to it — the device then holds only a short-lived access token, which is what it is designed to hold.