OAuth 2.0 Remote Consent
IAM will redirect the user to the configured remote consent URL to confirm OAuth 2.0 scopes.
The remote site must implement the Remote Consent Protocol. Please refer to the documentation for further information.
remoteConsentUrl) additionalClaims) signer) encrypter) validity) callbackUrl) verifier) decrypter) airlockGatewayRole) The Airlock Gateway (WAF) role / credential that is set when accessing the remote consent site.
This can be used when IAM and the remote consent site provider are behind the same Airlock Gateway and you want to restrict the access to the remote consent site by a specific Gateway mapping.
The name of the credential can be followed by a colon and the idle timeout of the credential in seconds, e.g. "myrole:300" sets the credential "myrole" that will expire after 5 minutes of client inactivity.
With a second colon and a second number, the life-time can be set, e.g. "myrole:300:3600" will set the credential "myrole" for a maximum of 1 hour, but it will also expire after 5 minutes of client inactivity.
type: OAuth2RemoteConsent
id: OAuth2RemoteConsent-xxxxxx
displayName:
comment:
properties:
additionalClaims:
airlockGatewayRole:
callbackUrl:
decrypter:
encrypter:
remoteConsentUrl:
signer:
validity: 1800
verifier: