<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

On-Behalf of Token Exchange Requires Use of Two Custom Authorization Servers

Okta Identity Engine
API Access Management

Overview

This article clarifies the requirements for implementing the OAuth 2.0 On-Behalf-Of (OBO) token exchange grant type and configuring custom authorization servers.

Applies To

  • API Access Management (API AM)
  • OAuth 2.0
  • OpenID Connect (OIDC)
  • Custom Authorization Servers

Cause

The inability to configure the OBO token exchange grant type or create custom authorization servers typically occurs when an Okta tenant lacks an active API Access Management (API AM) license.

Solution

To use the On-Behalf-Of Token Exchange grant type and create Custom Authorization Servers, the Okta tenant must have the API Access Management (API AM) license enabled. If this feature is not currently active, Okta administrators should reach out to their Okta Account Executive to discuss adding API Access Management to their subscription plan.

 

Once the API AM license is active, administrators can configure the necessary trust relationships. The On-Behalf-Of token exchange setup strictly requires creating two custom authorization servers and establishing a trust bond between them.

Related References

Loading
Okta Support - On-Behalf of Token Exchange Requires Use of Two Custom Authorization Servers