OAuth 2.0/OIDC Authorization Server
identifier) applicationUi) Defines which application UI will handle the authorization requests or redirect to a custom application UI.
This allows clients to use the URL (/<loginapp-uri>/oauth2/v3/<as-identifier>/authorize) from the OAuth 2.0 metadata to redirect to a custom application UI.
issuerId) The issuer ID of this AS.
This is used both for the metadata endpoint and the OIDC authorization code flow, therefore it must be configured when using either one.
It must end with a slash followed by the unique identifier of the AS.
Note that the issuer ID usually represents the front-facing URL of this authentication server and may be used by clients to derive the URL of the OpenID Connect Discovery or the OAuth 2.0 Metadata endpoint. See plugin documentation of those endpoints for more details about the logic and rules of this derivation.
oauth2Grants) staticClients) The statically configured clients of this AS.
In contrast to the "Persisted Clients", these clients are only contained in the configuration and are not stored on the database. This is useful when the entire set of clients is known upfront at configuration time.
Static clients can be combined with persisted clients. If both sources contain a client with the same name, the static client will take precedence without raising an error.
persistedClients) The persisted clients on the database of this AS.
This plugin is required when Dynamic Client Registration is used. Persisted clients are stored on the database and currently can only be inserted using Dynamic Client Registration.
Persisted clients can be combined with static clients. If both sources contain a client with the same name, the static client will take precedence without raising an error.
metadataEndpoint) Endpoint for OAuth 2.0 Authorization Server Metadata (RFC 8414).
The Endpoint is located at /<loginapp-uri>/rest/oauth2/authorization-servers/<as-identifier>/.well-known/oauth-authorization-server and must be mapped by a WAF or proxy to the external URL <issuer id>/.well-known/oauth-authorization-server
tokenEndpoint) Configuration of the token endpoint.
This endpoint is called by the clients in order to exchange an authorization code or to refresh a Refresh Token.
The token endpoint is located at /<loginapp-uri>/rest/oauth2/authorization-servers/<as-identifier>/token
tokenIntrospectionEndpoint) Endpoint for OAuth 2.0 Token Introspection (RFC 7662) located at /<loginapp-uri>/rest/oauth2/authorization-servers/<as-identifier>/introspect
tokenRevocationEndpoint) Endpoint for OAuth 2.0 Token Revocation (RFC 7009) located at /<loginapp-uri>/rest/oauth2/authorization-servers/<as-identifier>/revoke
dynamicClientRegistration) The OAuth 2.0 Dynamic Client Registration endpoint settings.
The registration endpoint must be configured in the Loginapp's settings for "Technical Client Registration", where a flow containing an "OAuth 2.0 Client Registration Step" can be configured.
resourceEndpoint) Configuration of all resource endpoints located at /<loginapp-uri>/rest/oauth2/authorization-servers/<as-identifier>/resources/<resource-name>
For all resource endpoints, a valid access token must be provided.
sessionManagementEndpoint) Endpoint for the custom OAuth 2.0 Session Management.
If not configured, the session management endpoint is disabled for this AS.
The session management endpoint is located under /<loginapp-uri>/rest/oauth2/authorization-servers/<as-identifier>/sessions/
discoveryEndpoint) Enables the OpenID Connect Discovery Endpoint.
The endpoint is available under /<loginapp-uri>/rest/oauth2/authorization-servers/<as-identifier>/.well-known/openid-configuration
This endpoint can only be configured when an OpenID Connect flow has been configured.
userInfoEndpoint) Enables the UserInfo Endpoint according to the OpenID Connect Specification.
The endpoint is available under /<loginapp-uri>/rest/oauth2/authorization-servers/<as-identifier>/userinfo
This endpoint can only be configured when an OpenID Connect flow has been configured.
openIdConnectSessionManagement) Enables OpenID Connect Session Management 1.0 according to the OpenID Connect Session Management Specification.
It allows a website relying on the user's authentication to monitor his login status at the OpenID Provider on an ongoing basis so that the Relying Party can log out an End-User who has logged out of the OpenID Provider.
Enabling this will allows the client to embed the OP-Iframe using the url /<loginapp-uri>/oauth2/v3/<as-identifier>/check-session
userStore) tokenDataProvider) sessionRepository) consentStorageRepository) If configured, enables storing user given consent in a database.
During an OAuth 2.0 flow, IAM can remember the scopes for which a user has given his consent and therefore skips the consent screen if all requested scopes were granted/denied in a previous flow.
This setting is required when a Local Consent is used with enabled Consent Storage.
usernameTransformation) Allows to convey a different username than the IAM user ID.
This transformed username is used in the following locations:
- OpenID Connect ID Token: sub claim
- OpenID Connect ID Token: Custom username claim
- Access Token as JWT: sub claim
- UserInfo Endpoint: sub claim
- Token Introspection Endpoint: sub claim
- Username Resource
The transformers are asked to provide an alternative name in the configured order. Every transformer may interrupt the transformation chain and provide a final result or pass it on to the next transformer to potentially apply further transformations.
If left blank, the username of the authenticated user is used for all endpoints mentioned above.
Note that this setting can be overridden for each "OAuth 2.0 Static Client".
roleTransformationConfigs) A list of role transformation rules used to modify the collection of roles to propagate.
The role transformation rules are executed at the following locations in-order from top to bottom:
- OpenID Connect ID Token
- Access Token as JWT
- UserInfo Endpoint
- User Roles Resource
tokenGeneratorConfig) loggingSettings) deleteTokensOnLogout) Configures which OAuth 2.0 / OpenID Connect tokens and sessions of the user are deleted when the user logs out:
- None: No tokens are deleted. Note that OpenID Connect Back-Channel Logout 1.0 is not supported in this case even if there are clients that specify a "Back-Channel Logout URI".
- Session: All tokens from the current user's session are deleted.
- All: All tokens of this user are deleted.
Note: If "Session" or "All" is selected, OpenID Connect Back-Channel Logout 1.0 is only performed for (client) sessions which are based on the current user's session.
Security Warning: Affects only actively triggered logouts, but not session timeouts. Therefore, the validity of each OAuth 2.0 token type should be configured and checked appropriately.
deleteTokensOnPasswordChange) deleteTokensOnUserLocked) Note: This setting only applies to users locked in the Loginapp. To delete tokens for users locked by admins, configure the corresponding settings within the Adminapp.
persistClaims) When not enabled, claim values are newly evaluated every time a new token is created. This may lead to different claim values every time a token is requested. This was the default behaviour in all IAM <= version 8.2 releases.
However, regardless of this setting, the following claims are always freshly evaluated every time a token is requested:
- iat - Issue Time
- nbf - Not Valid Before
- exp - Expiration Time (claim is not included if token has infinite validity)
- jti - JWT ID (random value)
- random - A random value for the token entropy
- scope - A JSON array defining the scope of the access token
- cnf - The token binding (if applicable)
Note: The column 'claims' in the database table 'oauth2_session' is required to use this feature. A runtime error occurs if this feature is active and the database was not migrated.
cacheControlResponseHeader) - /auth-login/rest/oauth2/authorization-servers/authorizationServerId/jwks/
- /auth-login/rest/oauth2/authorization-servers/authorizationServerId/.well-known/openid-configuration/
- /auth-login/rest/oauth2/authorization-servers/authorizationServerId/.well-known/oauth-authorization-server/
type: OAuth2AS
id: OAuth2AS-xxxxxx
displayName:
comment:
properties:
applicationUi:
cacheControlResponseHeader:
consentStorageRepository:
deleteTokensOnLogout: SESSION
deleteTokensOnPasswordChange: false
deleteTokensOnUserLocked: false
discoveryEndpoint:
dynamicClientRegistration:
identifier:
issuerId:
loggingSettings:
metadataEndpoint:
oauth2Grants:
openIdConnectSessionManagement:
persistClaims: true
persistedClients:
resourceEndpoint:
roleTransformationConfigs:
sessionManagementEndpoint:
sessionRepository:
staticClients:
tokenDataProvider:
tokenEndpoint:
tokenGeneratorConfig:
tokenIntrospectionEndpoint:
tokenRevocationEndpoint:
userInfoEndpoint:
userStore:
usernameTransformation: