OAuth 2.0 Token Request Authentication
Description
Extracts an OAuth 2.0 access token (bearer token) from a request to authenticate single requests.
May be used by
Properties
Authorization Server ID (
authorizationServerId) Description
The unique identifier of the OAuth 2.0 Authorization Server.
This must reference an Authorization Server in the top-level OAuth 2.0 Settings of the Loginapp.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Add Scopes As Roles (
addScopesAsRoles) Description
If enabled, the scopes from the Access Token are added as roles to the authenticated user.
Attributes
Boolean
Optional
Default value
true
User Store (
userStore) Description
If configured, the user is loaded from local persistence and checked for validity. Authentication fails if the user is not found or is invalid. If no user store is configured, no persistency look-up takes place and the authentication is performed on data contained within the credential only.
Attributes
Plugin-Link
Optional
Assignable plugins
Static Roles (
staticRoles) Description
Static list of roles granted to the authenticated user.
Attributes
String-List
Optional
Roles Blocklist (
rolesBlocklist) Description
List of role names that won't be granted to the authenticated user. The block list is also applied to persistent roles (if available).
Attributes
String-List
Optional
YAML Template (with default values)
type: OAuth2TokenRequestAuthentication
id: OAuth2TokenRequestAuthentication-xxxxxx
displayName:
comment:
properties:
addScopesAsRoles: true
authorizationServerId:
rolesBlocklist:
staticRoles:
userStore: