You are viewing an earlier version of the admin guide. For the latest version, please visit EmpowerID Admin Guide v7.211.0.0.
Add OAuth Scopes to applications
OAuth scopes limit the amount of access that users have to an application. In EmpowerID, managing OAuth scopes requires three key components: Web Services, which are REST APIs created in Workflow Studio and then published as protected app resources; an OAuth application configured for OAuth SSO; and an OAuth Provider application, responsible for issuing the ClientID, Client Secret, and API Key.
Scopes in EmpowerID are added to the OAuth application. This setup allows administrators to define custom OAuth scopes and assign relevant web services to these scopes. When an access token is requested with specified scopes, it grants access to all the web services associated with those requested scopes.
Procedure
Go to Apps and Authentication > Applications.
You can also search for applications using the global search.Locate the target OAuth application and click the Display Name link for it.
Â
On the Application Details page, select the SSO tab and expand the Scopes (OAuth) accordion.
Â
Click the Add button on the grid header.
Enter a name and description for the scope, and then click Save.
Â
Repeat steps 4 and 5 to add more scopes as needed.
Â
Â
Â