<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
On-Behalf of Token Exchange Requires Use of Two Custom Authorization Servers
Okta Identity Engine
API Access Management
Overview

This article clarifies the requirements for implementing the OAuth 2.0 On-Behalf-Of (OBO) token exchange grant type and configuring custom authorization servers.

Applies To
  • API Access Management (API AM)
  • OAuth 2.0
  • OpenID Connect (OIDC)
  • Custom Authorization Servers
Cause

The inability to configure the OBO token exchange grant type or create custom authorization servers typically occurs when an Okta tenant lacks an active API Access Management (API AM) license.

Solution

To use the On-Behalf-Of Token Exchange grant type and create Custom Authorization Servers, the Okta tenant must have the API Access Management (API AM) license enabled. If this feature is not currently active, Okta administrators should reach out to their Okta Account Executive to discuss adding API Access Management to their subscription plan.

 

Once the API AM license is active, administrators can configure the necessary trust relationships. The On-Behalf-Of token exchange setup strictly requires creating two custom authorization servers and establishing a trust bond between them.

Related References

Loading
On-Behalf of Token Exchange Requires Use of Two Custom Authorization Servers