OAuth Resource Indicators
Use an OAuth resource indicator to identify the target OAuth resource server in a token request.
Use the resource request parameter to identify the target resource server and the scope parameter to request its permissions.
Configure a Resource Server
For an OAuth resource application, resource is the primary identifier used by resource-indicator requests. The resource indicator must uniquely identify the OAuth resource application in the identity domain.
The audience value identifies the base URI used to construct fully qualified scopes (FQS). If an application has a resource value and no audience value, the token audience uses the resource value. If both values are configured, audience remains the token audience.
For example, an Apps payload can include the following values:
{
"audience": "aud1",
"resource": "https://test2.com",
"isOAuthResource": true
}
Request a Token
The prepared token example applies to the client credentials grant. Include both resource and scope in the request. When resource identifies the target resource server, the scope can use scope literals instead of FQS values. A request can include multiple scope literals for the same target resource server, separated by spaces.
curl --request POST 'https://tenant1.identity.internal.oracle.com:8943/oauth2/v1/token' \
--user 'ClientID:ClientSecret' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode 'grant_type=client_credentials' \
--data-urlencode 'scope=test4' \
--data-urlencode 'resource=https://test2.com'
The request can use the primary resource value. When the request includes an FQS and a scope literal, the FQS audience must match the audience associated with the target resource server.
Validate Requested Scopes
The authorization server validates every requested scope against both the OAuth client's allowed scopes and the target resource server's scopes. A request that identifies one resource server but requests a scope that belongs only to another resource server fails validation.
Requests that omit resource and use FQS values continue to use the existing scope-based model.
Understand Token Claims
The aud claim in the access token is the target resource application's audience value. The resource value will not be in the access token claims.
For a resource application with resource=https://test2.com, audience=aud1, and scope test4, a request with resource=https://test2.com and scope=test4 can return an access token such as the following:
eyJhdWQiOiJhdWQxIiwic2NvcGUiOiJ0ZXN0NCIsIm90aGVyX2NsYWltcyI6Ii4uLiJ9
When decoded, the relevant claims are as follows:
{
"aud": "aud1",
"scope": "test4",
"other_claims": "..."
}