cancel
Showing results for 
Search instead for 
Did you mean: 

Authentication using JWT in SAP API Management

12-04-2024 11:17 AM
faisaljamal1 Explorer
898 views 1 comments
0 Likes
SAP Managed Tags
Labels
JWTOAuth 2.0
Subscribe

Hello Experts,

We are in a process of implementing OAuth(client credentials based) authentication to API proxies using the JWT verify policy in SAP API Management as described in this post. We used EntraID as IdP. We have been able to successfully implement and test it, but have an observation though. 

We noticed during testing that token fetched for app registered for Dev environment is also working for authenticating with API proxy in SAP APIM Test environment, which is most likely because both the APIs (dev and test) are registered in a common EntraID. 
But is this how it should work? Is there a way to ensure that token fetched for API in one environment does not works for APIs in another environment?

Any inputs will be appreciated. Thanks!

Regards,

Faisal

 

0 Likes

Accepted Solutions (0)

Answers (0)