This site contains the documentation that is relevant to older WSO2 product versions and offerings.
For the latest WSO2 documentation, visit https://wso2.com/documentation/.
Try Password Grant
The Password Grant is one of the four grant types in the OAuth 2.0 specification. For more information about this grant type, see Resource Owner Password Credentials Grant.
Running the application
Before you begin, you must first set up the sample webapp.
- Visit the URL http://wso2is.local:8080/playground2/oauth2.jsp to start the application.
Enter the following details and click Authorize.
Authorization Grant Type: Resource Owner
Client ID: (the client id received at the application registration)
Client Secret: (client secret received at the application registration)
Resource Owner User Name: (username)
Resource Owner Password: (password of the user)
Authorize Endpoint: https://localhost:9443/oauth2/tokenIf you have configured the service provider in a tenant, you have to add the tenant domain as a query parameter to the access token endpoint.
If the tenant domain is wso2.com, access token endpoint will be as follows.
Access Token Endpoint: https://localhost:9443/oauth2/token?tenantDomain=wso2.com
At this point the application receives the Access Token. Enter the introspection endpoint (i.e, https://localhost:9443/oauth2/introspect) and click Get TokenInfo to get the token information.
Now you should be able to see the access token information as seen below, as long as the provided access token is valid.
- See Invoke the OAuth Introspection Endpoint to invoke the OAuth introspection endpoint using cURL commands.