Configuring OAuth 2.0


As an administrator, configure OAuth 2.0 in any of the following cases:  

  • You have applications that act as OAuth clients and interact with applications protected by BMC Helix SSO.
  • You have applications hosted on different top-level domains integrated with the same BMC Helix SSO server. 


Complete the following tasks to configure OAtuth 2:

Task

Description

Depending on your application type, you must register your application as a native or non-native OAuth client. 

Configure the token timeouts for the client application.

View and delete tokens of active user sessions. 

Generate JSON Web Keys (JWK)  to support multiple domain applications when BMC Helix SSO server is used as an OAuth server.

Map the attributes extracted from an IdP response to custom claims.

Configure Content Security Policy (CSP) headers in an HTTP response from the /authorize and /consent-decision endpoints.


 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*