Configuring OAuth 2.0 Target Security

After Enterprise Connector is enabled for an endpoint, you can configure OAuth 2.0 as the target security method. This configuration enables the Hybrid Service to acquire an OAuth 2.0 Bearer token from the external authorization server and include it in outbound requests.

Configuring Client Credentials

Use Client Credentials when the target API requires machine-to-machine authentication with no user context.

  1. Navigate to API Gateway > Available APIs.
  2. Open the API suite that contains the Enterprise Connector-enabled endpoint.
  3. Open the target endpoint configuration page.
  4. In the Target Security section, select OAuth2.0.
  5. Select Client Credentials as the grant type.
  6. Specify this information:
    Token URL
    Specify the external authorization server token endpoint.
    Client ID
    Specify the OAuth 2.0 client identifier issued by the external service.
    Client Secret
    Specify the OAuth 2.0 client secret issued by the external service.
    Scope
    Optionally, specify a space-separated list of scopes to request.
  7. Click Save.

Configuring Resource Owner Password Credentials (ROPC)

Use ROPC when the target API requires user-level authentication and does not support interactive login flows.

  1. Navigate to API Gateway > Available APIs.
  2. Open the API suite that contains the Enterprise Connector-enabled endpoint.
  3. Open the target endpoint configuration page.
  4. In the Target Security section, select OAuth2.0.
  5. Select Resource Owner Password Credentials as the grant type.
  6. Specify this information:
    Token URL
    Specify the external authorization server token endpoint.
    Client ID
    Specify the OAuth 2.0 client identifier.
    Client Secret
    Specify the OAuth 2.0 client secret.
    Username
    Specify the resource owner's username.
    Password
    Specify the resource owner's password.
    Scope
    Optionally, specify a space-separated list of scopes to request.
  7. Click Save.