Skip to main content
Version: v0.25.0 (Latest)

Authorization servers: Resource settings

The Authorization Servers area lists the tenant's hosted and external resources. Each row represents one stable authorization-server UUID. The UUID, not the display slug or issuer URL, is used by settings, clients, identities, federation bindings, and credential-issuer selections.

Open the area​

NavigationProtocols, Authorization Servers
Resource link#tenant={tenantId}&surface=as&instance={authorizationServerId}&tab=settings&section=tokens
ScopeCustomer tenant

The platform tenant's built-in authorization server is isolated and does not appear in this resource list.

Read the list​

The list shows deployment type, lifecycle, issuer, purposes, discovery freshness, and default roles. Hosted resources display their authentication mode. External resources display the last discovery outcome and expiry time.

Use the lifecycle filter to find draft, suspended, or decommissioned resources. Use the deployment filter to separate hosted servers from external OAuth and OIDC providers.

Create a hosted resource​

Choose Create authorization server, then select Hosted. Enter a display name, route slug, issuer, purposes, allowed grants, and authentication mode.

Hosted authentication modes are:

  • Local only uses hosted identities and does not present an upstream provider.
  • Federated only requires at least one valid enabled upstream binding before activation.
  • Hybrid offers local sign-in and the valid enabled upstream bindings.

Creating or reactivating a hosted resource evaluates the hosted authorization-server entitlement and reserves quota. Route, issuer, and live slug uniqueness are enforced per tenant. Signing configuration uses a typed KMS resource and key alias. Secret or key material is never returned by the page.

A hosted resource cannot declare usages. usages describes what an upstream server is relied on for, which only makes sense for an external resource. A hosted create that carries a non-empty usages list is rejected with Hosted authorization servers cannot declare external usages rather than having the field ignored. A hosted server's role comes from its purposes, its bindings and the issuers that select it.

Create an external resource​

Choose External, enter its issuer and the capabilities you expect discovery to prove, then create the resource. The service discovers and reconciles the issuer before it commits the resource. A discovery failure leaves no partial resource. Activation remains an explicit lifecycle operation. External resources do not consume hosted authorization-server quota.

Use Validate discovery to inspect the current source without changing the resource, and use Refresh discovery to replace its validated snapshot. The validation panel shows the reconciled OAuth and OpenID metadata, supported grants and scopes, client-authentication methods, discovery endpoints including UserInfo when advertised, source digest, validation time, expiry time, and any compatibility issue. The callback uses the persisted UserInfo endpoint to require subject consistency with the validated ID Token. An advertised RFC 7591 registration endpoint is retained only as discovery evidence. Dynamic client registration is not an administration operation in this release. A stale snapshot cannot support an enabled federation binding.

An external OAuth2-only resource can protect a compatible OID4VCI authorization flow. It cannot authenticate a hosted user. Hosted sign-in requires validated OIDC capability and an explicit binding.

Change lifecycle​

The resource header exposes only transitions valid for the current state.

  • Activate makes a valid resource available for new selections. Hosted activation checks entitlement and quota. External activation requires valid discovery.
  • Suspend stops new use while retaining configuration and dependent records for remediation.
  • Decommission is terminal. Remove or replace federation and issuer dependencies before confirming it.

Delete is available only when the resource has no protected dependencies and the lifecycle permits removal. The console shows dependency conflicts instead of silently detaching consumers.

Hosted configuration and signing​

For a hosted resource, the Settings tabs edit the runtime configuration selected through its configuration binding. The stored oauth2.servers.<slug>.* values are a generated runtime projection. They are not the lifecycle authority.

Signing changes require a tenant-visible KMS resource and key alias. The console writes only typed references and displays no private key. Configuration updates use the current revision so a stale browser cannot overwrite a newer save.

Federation bindings​

The Federation tab appears for hosted resources. It shows each external target, order, validation state, client-authentication method, scopes, and enabled state. Create and validate a binding before enabling it. Reordering changes the provider chooser without changing resource identity. Configure an operator-provisioned upstream client identifier and its typed secret or KMS reference on the binding. Raw credentials are accepted only as a write-once value and are never returned.

For detailed prerequisites and operating steps, see Hosted sign-in and external federation.

Migration remediation​

Resources converted from the retired tenant IdP registry start suspended and unbound. The migration detail identifies the retained non-secret client ID, scopes, claim mapping, and former enabled state. Validate discovery, supply a typed credential reference, attach the intended hosted resource, validate the binding, and enable it. The console never re-enables a migrated provider automatically.

Hosted resources converted from RC3 keep their issuer, route, clients, identities, system/default role, and runtime configuration. Their public selector changes to the stable resource UUID.

REST operations​

The page uses the platform-config operations below:

  • listAuthorizationServers, createAuthorizationServer, getAuthorizationServer, and updateAuthorizationServer
  • activateAuthorizationServer, suspendAuthorizationServer, and decommissionAuthorizationServer
  • validateExternalAuthorizationServer and refreshExternalAuthorizationServerDiscovery
  • getHostedAuthorizationServerConfiguration and replaceHostedAuthorizationServerConfiguration
  • getHostedAuthorizationServerSigning and replaceHostedAuthorizationServerSigning
  • the nested federation-binding operations below the selected authorizationServerId

See the Platform Config REST reference for exact request and response schemas.