Creating an Oracle Identity Cloud Service (IDCS) Application
As a Service Administrator, you must create an Oracle Identity Cloud Service (IDCS) application and provide the connection credentials to your users so that they can use the organization's sign in credentials to connect to their business processes from Oracle Smart View for Google Workspace.
Follow this procedure only if your users want to use the organization's sign in credentials to access their business process servers from Smart View. This procedure is not required if your users are native users using basic authentication such as a user name and password.
While connecting using their organization's sign in credentials, users enter Server URL, Client ID, IDCS URL, and Scope in the Connect dialog box.
As a Service Administrator, ensure that you configure and share these connection credentials with your users:
-
Server URL: This refers to the web application link of your Oracle Fusion Cloud Enterprise Performance Management business process server.
Modify the web application link to remove "/epmcloud" and add "/HyperionPlanning" towards the end of the URL.
-
Client ID: This is generated as part of the IDCS application creation process.
To find the Client ID in the Oracle Cloud Console, go to Identity domains and click Integrated applications. Click your IDCS application link, and in the OAuth configuration tab under General Information, see the value in the Client ID field.
-
IDCS URL: This is the URL that you get on the Sign In page when you open your Cloud EPM web application.
Modify the link to retain it till "identity.oraclecloud.com" and remove the characters after this part. For example,
https://idcs-<instanceID>.identity.oraclecloud.com. -
Scope: This determines the resources available for each application. The scope is added as part of the IDCS application creation process. See Scope under Step 2: Configuring Authentication
Users work on multiple environments and keeping track of credentials for different environments may become difficult. As a Service Administrator, you can simplify this process by creating a connections JSON file and distributing it to your users. See Sharing Connection Credentials Using JSON File.
The process of creating an IDCS application is a one-time configuration. It involves the following tasks:
- Step 1: Creating an IDCS mobile application
- Step 2: Configuring authentication
- Step 3: Activating the application
Step 1: Creating an IDCS Mobile Application
Create and add a custom application for each business process that your users want to access through Smart View. There are various types of custom applications. For the purpose of Smart View, you need to create a Mobile application.
Click Add application and select Mobile Application. Launch the workflow to enter a name and description for the application and submit it. The Details tab displays the application details.
For more information, see Adding Applications and Adding a Mobile Application in Oracle Cloud Infrastructure documentation.
Step 2: Configuring Authentication
Once your application is created, you can configure the authentication details on the OAuth configuration tab by clicking Edit OAuth configuration.
The following configurations are specific to Oracle Smart View for Google Workspace:
Grant Types:
A grant type is a standard method to obtain access tokens for accessing protected resources and requesting validation. In Client configuration section, under Authorization, select the following grant types from the Allowed grant types list:
- Refresh token
- Device code
- Authorization code
Redirect URL:
It is the application URL where the user is redirected after authentication. The user needs to be redirected back to the Smart View extension in Google Sheets application. In Client configuration section, under Redirect URL section, enter the following URL in the Redirect URL field:
https://script.google.com/macros/d/1Q3Fr7T8V1PWSzgDWmqsIKlyzix0i4weESTVgkiC_gxIH1H57T9WdOXBU/usercallback
Scope:
Scope determines the resources available for each application. Resource refers to the Cloud EPM business processes servers that your users access through Google Sheets. In the Token Issuance policy section, enable Add Resources, and click Add Scope to select the Cloud EPM business process servers for adding scope. Following is an example of the format of scope:
urn:opc:serviceInstanceID=<SERVICE_INSTANCE_ID>urn:opc:resource:consumer::all offline_access
Note the scope associated with each selected resource. You need to provide this value to your users as part of connection credentials.
While sharing this value, including through a connection JSON file, ensure that
offline_access is appended toward the end. Add as a space after
::all and then add offline_access. Appending
offline_access enables users to obtain new access tokens after
their usual tokens expire, thus reducing reauthentication and frequent sign-ins.
If offline_access is not appended in the
Scope field, then while connecting to their business
process from Google Sheets, users get a message "Access will not be refreshed
after session expiry as offline_access is not added to Scope. Continue
session without generating refresh tokens?". They can click
Yes, to continue connecting without generating refresh
tokens, and be ready for prompts to authenticate again after session expiry. Else,
they can click No, to go back and append
offline_access in the Scope field.
Allow token refresh:
If you have selected Refresh Token as a grant type and
appended offline_access in the Scope field
but you have not enabled Allow token refresh to prevent
session expiry, then while connecting to their business process from Google Sheets,
users get an error message "Service Administrator has not enabled refreshing of
access tokens for this instance". So ensure that you enable
Allow token refresh under Resource server
configuration to facilitate automatic generation of refresh tokens.
For more information on other configurations, see the following topics:
- Authentication with OAuth 2 in REST APIs for Oracle Fusion Cloud EPM
- Configuring OAuth in Oracle Cloud Infrastructure documentation
- Knowledge Article on My Oracle Support (MOS): Update OAuth 2.0 Configuration and Obtain a New Refresh Token for Oracle Cloud EPM (26.07) to Resolve - 401 Unauthorized Error
Step 3: Activating the application
You can activate the application you created, so that it is available for users. On the application page, under the application name, click Activate.
For more information, see Activating an Application in Oracle Cloud Infrastructure documentation.