on 2024 Dec 04 10:17 AM
Hello Experts,
We are in a process of implementing OAuth(client credentials based) authentication to API proxies using the JWT verify policy in SAP API Management as described in this post. We used EntraID as IdP. We have been able to successfully implement and test it, but have an observation though.
We noticed during testing that token fetched for app registered for Dev environment is also working for authenticating with API proxy in SAP APIM Test environment, which is most likely because both the APIs (dev and test) are registered in a common EntraID.
But is this how it should work? Is there a way to ensure that token fetched for API in one environment does not works for APIs in another environment?
Any inputs will be appreciated. Thanks!
Regards,
Faisal
Request clarification before answering.
| User | Count |
|---|---|
| 17 | |
| 8 | |
| 8 | |
| 6 | |
| 4 | |
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 2 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.