<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Question Re: Authentication using JWT in SAP API Management in Technology Q&amp;A</title>
    <link>https://community.sap.com/t5/technology-q-a/authentication-using-jwt-in-sap-api-management/qaa-p/13965776#M4896541</link>
    <description>Hello Experts, any suggestions on this please?</description>
    <pubDate>Tue, 17 Dec 2024 13:11:03 GMT</pubDate>
    <dc:creator>faisaljamal1</dc:creator>
    <dc:date>2024-12-17T13:11:03Z</dc:date>
    <item>
      <title>Authentication using JWT in SAP API Management</title>
      <link>https://community.sap.com/t5/technology-q-a/authentication-using-jwt-in-sap-api-management/qaq-p/13955207</link>
      <description>&lt;P&gt;Hello Experts,&lt;/P&gt;&lt;P&gt;We are in a process of implementing OAuth(client credentials based) authentication to API proxies using the JWT verify policy in SAP API Management as described in &lt;A href="https://community.sap.com/t5/technology-blogs-by-sap/part-1-modeling-the-jwt-token-verification-flows-in-sap-cloud-platform-api/ba-p/13419841" target="_self"&gt;this&lt;/A&gt;&amp;nbsp;post. We used EntraID as IdP. We have been able to successfully implement and test it, but have an observation though.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We noticed during testing that token fetched for app registered for Dev environment is also working for authenticating with API proxy in SAP APIM Test environment, which is most likely because both the APIs (dev and test) are registered in a common EntraID.&amp;nbsp;&lt;BR /&gt;But is this how it should work? Is there a way to ensure that token fetched for API in one environment does not works for APIs in another environment?&lt;/P&gt;&lt;P&gt;Any inputs will be appreciated. Thanks!&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 10:17:10 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/authentication-using-jwt-in-sap-api-management/qaq-p/13955207</guid>
      <dc:creator>faisaljamal1</dc:creator>
      <dc:date>2024-12-04T10:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication using JWT in SAP API Management</title>
      <link>https://community.sap.com/t5/technology-q-a/authentication-using-jwt-in-sap-api-management/qaa-p/13965776#M4896541</link>
      <description>Hello Experts, any suggestions on this please?</description>
      <pubDate>Tue, 17 Dec 2024 13:11:03 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/authentication-using-jwt-in-sap-api-management/qaa-p/13965776#M4896541</guid>
      <dc:creator>faisaljamal1</dc:creator>
      <dc:date>2024-12-17T13:11:03Z</dc:date>
    </item>
  </channel>
</rss>

