
JR.56041 (-) asked a question.
Hi All,
We have an application that has been created as: API Services, for token generation using client-credentials.
The Authorization server allows us to create Access Policies, however there isn't any way to use an access policy to restrict access by network zones.
Is there another approach to achieve this?

Hi @JR.56041 (-) , Thank you for reaching out to the Okta Community!
You can look into enabling the Network Restrictions for OAuth Token Endpoint feature to see if this helps with your use case.
Once enabled it, you should see the option under Okta Admin Dashboard > Applications >Applications > " API service app name" > General.
If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you.
Hope my answer helps!
--
Help others in the community by liking or hitting Select as Best if this response helped you.
Collect them all. Learn a new skill and earn a new Okta Learning badge.
Just released: More Okta Community badges just added
Join the discussion for our Ask Me Anything on September 29, 2025: Device Assurance. Ask our expert questions.