---
sourceDocument: Brazil Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/platform-security

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Restrict oauth parameters to POST body

# Restrict oauth parameters to POST body {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read  
Use the glide.oauth.allow.parameters.in.post.body.only property restricts OAuth credentials to POST request bodies when set to <kbd class="ph userinput">true</kbd>.
Use the glide.oauth.allow.parameters.in.post.body.only property to control how the OAuth token endpoint (/oauth_token.do) accepts OAuth credentials. When set to <kbd class="ph userinput">true</kbd>,
this property restricts OAuth parameters (such as client_id, client_secret, authorization codes, and refresh tokens) to POST request bodies only. OAuth credentials submitted using HTTP headers continue to be accepted.

To set up this property:

1. Navigate to /sys_properties_list.do on the ServiceNow instance.
2. Ensure glide.oauth.allow.parameters.in.post.body.only exists and is set to <kbd class="ph userinput">true</kbd>.

## More information {#sc-restrict-oauth-parameters-to-post-body__section_qhx_1b1_xwb}

{#sc-restrict-oauth-parameters-to-post-body__table_ajc_b43_3kb__entry__2}

| Attribute | Description |
|-|-|
| Configuration name | glide.oauth.allow.parameters.in.post.body.only |
| Configuration type | System Properties (/sys_properties_list.do) |
| Data type | Boolean |
| Recommended value | true |
| Fallback value | false |
| Default value | true |
| Category | [Data protection](https://www.servicenow.com/docs/V~KXGFQil6~fjraiRnJvpw "The data protection category addresses the elements of confidentiality, integrity and availability (CIA) of data.") |
| Security risk | * Severity score: 4.2 * CVSS score: Medium * Security risk details: If glide.oauth.allow.parameters.in.post.body.only isn't set to the recommended value of true, OAuth credentials such as client_id, client_secret, authorization codes, and refresh tokens could be present in the URL query string. These credentials could linger in client and infrastructure logs and potentially lead to account takeover if those logs are leaked. {#sc-restrict-oauth-parameters-to-post-body__ul_g1g_3sf_xwb} |
| Dependencies and prerequisites | Plugin OAuth 2.0 |
| References | * [OAuth 2.0](https://www.servicenow.com/docs/_OwIX8WTKra9vkrYhUuQEg "OAuth 2.0 lets users access instance resources through external clients by obtaining a token rather than by entering login credentials with each resource request.") * [Manage OAuth tokens](https://www.servicenow.com/docs/03kMjUQPB0qN9Ejnif1zgA "Open OAuth tokens to provide access to restricted resources.") {#sc-restrict-oauth-parameters-to-post-body__ul_sqb_nnp_myb} |
| Functional impact | Ensures that oauth_token.do processor accepts only POST body parameters as input for all supported grant types. |
[ ]

{#sc-restrict-oauth-parameters-to-post-body__table_ajc_b43_3kb}

