OAuth Scope Not Blocking Access to Other CSM APIs Despite Scope Restriction
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
6 hours ago
I've configured an OAuth client in ServiceNow and assigned a scope that is limited to the "Contact" API. A standard user with the role "sn_customerservice_agent" generates an access token using this scope. The token is created successfully.
However, using this token, the user can still access the "Case" API, even though that scope is not included.
Is there a way to restrict the API access using scopes?
0 REPLIES 0
