When should you use it?
Due to the high level of risk associated with this grant type, it should only be used when both the authorization code grant and implicit grant are unavailable. This grant type is well-suited for migrating existing clients using direct authentication schemes such as HTTP basic or digest authentication to an OAuth 2.0 flow since it makes use of the same stored credentials that those legacy authentication methods use.