Understanding Web Credentials

Use Web credentials to connect to external REST services or REST Enabled SQL services.

Creating Web Credentials securely stores and encrypts authentication credentials for use by Oracle APEX components and APIs. Credentials cannot be retrieved back in clear text. Credentials are stored at the workspace-level and therefore are visible in all applications.

See Also: Managing REST Enabled SQL References

Protecting Web Credentials by Defining Valid URLs

Protect Web credentials by adding valid URLs.

You can optionally protect Web credentials by adding valid URLs to the Valid for URLs attribute. Adding URLs to the Valid for URLs attribute prevents APEX from accidentally sending sensitive credentials to a different server. Whenever a Web credential is used, APEX checks whether the URL matches what is defined in the Valid for URLs attribute. If the URL does not match, APEX raises the runtime error, Credential is not allowed to be used for this URL endpoint.

When adding URLs to this attribute, place each URL into a new line. The URL endpoint being used must start with one of the URLs provided here. See field-level Help for examples.

About Supported Authentication Types in Web Credentials

Learn about supported authentication types in Web credentials.

Web credentials support the following Authentication Types:

Note: If the token server issued a Refresh Token, that refresh token will be used to refresh an expired access token.

Using a Database Credential with Web Credentials

Learn about using a database credential with Web credentials.

Note: This feature is only available on Oracle Database release 26ai or Autonomous Database release 19c or later.

For Oracle Database 26ai or Autonomous Database 19c or later, Web credentials can reference a database credential to store the details when the Web credential is of the Basic Authentication, OAuth2 Client Credentials, or OCI Native Authentication type. Database Credentials can also be used for Signed User Assertion credentials. Other Web credential types do not support database credentials.

Using a database credential changes the behavior of HTTP requests being made and how Web credentials work:

Tip: You can maintain a database credential using the DBMS_CREDENTIAL or DBMS_CLOUD packages.

About Instance and Schema Database Credentials

If a Web credential references a database credential, the database credential must be accessible to the application’s parsing schema. If the INSTANCE_DBMS_CREDENTIAL_ENABLED instance parameter is enabled (set to the ‘Y’ value), then a database credential, which is accessible to the APEX engine schema (APEX_NNNNNN) can be used in all workspaces.

See Also: INSTANCE_DBMS_CREDENTIAL_ENABLED in Available Parameter Values, APEX_INSTANCE_ADMIN in Oracle APEX API Reference

Exporting and Importing Web Credentials

Learn about exporting and importing Web credentials.

When you export an application, used credentials are added to the export file. When you import the application into another workspace, APEX checks whether the target workspace already contains credentials with the same static ID. If a credential already exists, the application uses it. Otherwise the credential from the import file is created in the target workspace.