<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00006G4m3JSAROkta Classic EngineAdministrationAnswered2024-04-15T10:48:07.000Z2019-05-14T16:36:29.000Z2019-06-04T22:13:06.000Z

kph1g (kph1g) asked a question.

Restrict OAuth Client Credentials Flow (headless/server-to-serv) to only add/remove specific user to specific group

A user has requested API access to okta for a proof-of-concept application.

They have a test user, a test group, and a test OAuth application in Okta.

How do I restrict their OAuth application (in Okta) to only access the test user, the test group, and the "groups" api resource? (https://developer.okta.com/docs/api/resources/groups/*add-user-to-group). I've read a lot of documentation and it's unclear which features to use in which order.


Loading
Restrict OAuth Client Credentials Flow (headless/server-to-serv) to only add/remove specific user to specific group