<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00006PIeFySALOkta Classic EngineAdministrationAnswered2024-04-15T10:05:02.000Z2019-07-02T22:07:18.000Z2019-07-17T04:55:48.000Z

fagiz (fagiz) asked a question.

Restricting application from use with the Okta org authorization server

When creating an oauth application, it's possible to restrict it from use in a given custom authorization server by setting up policy rules for the custom authorization server. However, there doesn't seem to be a way to prevent using the application with the "Okta org as an authorization server" - the one with urls like https://example.okta.com/oauth/v1/token, rather than https://example.okta.com/oauth/aus.../v1/token or https://example.okta.com/oauth/default/v1/token.

 

Is there any way to restrict this accesss? We have some applications for using password grant against test auth servers, or for client credentials grant, and it seems like these should not be useable witht he "Okta org an an authorization server". Even if that server is only for authentication as opposed to authorization, it still feels like a potential security vulnerability.


This question is closed.
Loading
Restricting application from use with the Okta org authorization server