Writing Custom Grant Types

This site contains the documentation that is relevant to older WSO2 product versions and offerings.
For the latest WSO2 documentation, visit https://wso2.com/documentation/.

Writing Custom Grant Types

OAuth 2.0 authorization servers provide support for four main grant types according to the OAuth 2.0 specification. They also allow you to add custom grant types and extend the existing ones.

See Writing a Custom OAuth 2.0 Grant Type in the WSO2 identity Server documentation to implement custom grant types for the API Manager. Note that API Manager has already customized the Grant Type handlers for authorization_codepasswordclient_credentials and saml2-bearer grant types. If you require any additional functionality for these grant types, its advisable to extend the following grant handler implementations. 

Grant Type

Existing Handler Class (which can be extended if required)

authorization_code

org.wso2.carbon.apimgt.keymgt.handlers.ExtendedAuthorizationCodeGrantHandler

password

org.wso2.carbon.apimgt.keymgt.handlers.ExtendedPasswordGrantHandler

client_credentials

org.wso2.carbon.apimgt.keymgt.handlers.ExtendedClientCredentialsGrantHandler

urn:ietf:params:oauth:grant-type:saml2-bearer

org.wso2.carbon.apimgt.keymgt.handlers.ExtendedSAML2BearerGrantHandler

Are you using WSO2 Identity Server as the Key Manager? If so, be sure to follow the this compatibility matrix.