Beta

Create a tenant

A new tenant starts with its own users, OAuth settings, audit history and logs. You are its first Tenant Admin.

BTL Admin

OAUTH 2.0 · LAB

Read a client registration as a set of rules

Map each line of the printer's registration to a request it allows or refuses, suspend one client without affecting its sibling, and see that a client ID means something only to its issuer.

ReadyUses your lab tenant

The lesson

Builds on: Choosing a flow.

New to the labs? Start with the lab toolkit and the shared cast and names every lab uses.

Your progress

Press Start before you begin. Only events your tenant records after that count, in the order below. Checking reads your tenant's Audit, so you need Audit read access in it.

  1. A scope outside the registration is refused

    Recorded as oauth.token rejected (invalid_scope) for lab-print-orders.

  2. Suspend the printer

    Recorded as tenant.oauth.clients.update succeeded.

  3. The suspended printer cannot authenticate

    Recorded as oauth.token rejected (client_disabled) for lab-printer.

  4. The printer's public app keeps working

    Recorded as oauth.token succeeded for lab-printer-app.

  5. Re-enable the printer

    Recorded as tenant.oauth.clients.update succeeded.

Request console

Requests in this lab can be sent from this page to your tenant: open one and choose Send. Fill in the values below first. They stay in this page's memory and are gone when you leave; secrets are never stored or sent anywhere except the request you send.

Setup

  1. Set the shell variables: ISSUER, PRINTER_ID and PRINTER_SECRET for lab-printer, ORDERS_ID and ORDERS_SECRET for lab-print-orders, APP_ID for lab-printer-app, API_ID and API_SECRET for lab-photo-api, and enc.

  2. Get a current printer access token for Ava with the code flow from the authorization code labs, and keep it as TOKEN.

  3. Press Start on this page.

Walkthrough

  1. Open OAuth > Clients > lab-printer > View and write its registration in the lesson's format. Read the authentication method from discovery's token_endpoint_auth_methods_supported.

Client ID: <generated by the tenant, not chosen>
Client type: confidential
Redirect URIs: http://127.0.0.1:8765/callback, https://beyondthelogin.dev/lab/callback/
Grant types: authorization_code, refresh_token
Scopes it may request: every common scope (Restrict scopes is off)
Client authentication: client_secret_basic

Do the same for lab-print-orders: confidential, no redirect URIs, client_credentials, only prints.create (Restrict scopes is on), client_secret_basic.

Why it matters: each line is a rule the authorization server applies to every later request, not paperwork.

  1. Turn lines into requests that fall outside them.

    • Grant type: client credentials as the printer answers unauthorized_client, as in the Choosing a flow lab.

    • Redirect URI: an authorization request for the printer with https://beyondthelogin.dev/lab/callback (no trailing slash) stops on the tenant's error page.

    • Scopes: curl -s -u "$ORDERS_ID:$ORDERS_SECRET" -d grant_type=client_credentials -d scope=photos.read "$ISSUER/oauth/token" | jq answers invalid_scope. This server rejects the request rather than silently dropping the scope.

Why it matters: a request outside the registration never reaches consent, policy or the API.

  1. Suspend one client. Open OAuth > Clients > lab-printer > Edit, untick Enabled and save. The editor warns that saving revokes the client's tokens, codes and remembered consent.

    • An authorization request for the printer stops on the tenant's error page.

    • Client authentication as the printer, for example curl -s -i -u "$PRINTER_ID:$PRINTER_SECRET" -d grant_type=refresh_token -d refresh_token=x "$ISSUER/oauth/token", answers 401 invalid_client, "Client authentication failed. Check the client ID and secret, and that the client is enabled."

    • btl-lab introspect "$TOKEN" answers {"active": false} for the token issued before the change.

  1. The sibling keeps working. Run the public app's loopback flow from the Public and confidential clients lab with lab-printer-app, as Ava. It succeeds.

Why it matters: one registration per deployment lets the photo service suspend exactly the client that misbehaves, without breaking its siblings.

  1. Re-enable the printer: tick Enabled and save. TOKEN stays inactive. Turning a client on restores nothing it lost.

Restore: confirm lab-printer shows Enabled.

  1. Optional, with Lab Mail: use PRINTER_ID in an authorization request to $ISSUER2. It stops on that tenant's error page as an unknown client. The ID means something only to the issuer that created it.

  1. Registration through an API is not offered here yet.

POST$ISSUER/oauth/register Open in console
POST $ISSUER/oauth/register HTTP/1.1
Content-Type: application/json

{}

The answer is 501. Clients in this tenant are created by an administrator; dynamic registration is gap G9.

Break it

Step 3 is the deliberate suspension, and step 5 restores it.

Check your work

Press Check my progress. Logs also has oauth.authorize rejected invalid_client for the suspended client's authorization request, and oauth.register rejected not_implemented with status 501.

Cleanup

  1. Confirm lab-printer is Enabled.

There is no list yet of the people who connected a client (G40). Changing a client's settings clears its remembered consent instead.

Back to all labs

We value your privacy

We use cookies and similar technologies to enhance your browsing experience, and analytics to understand our traffic. By clicking "Allow All", you consent to optional analytics. Cookie Policy

The Lab