OAuth Client Credentials - Westpac
Condeco currently have API that requires authentication with OAuth 2 password grant type. Unfortunately, it is not aligned with Westpac Digital Platform (WDP) standards, as “PASSWORD” is not a supported grant type, and it is not secure (basic authorization which is passed in HTTP header). The requirement for Westpac is for Condeco to accept “Client Credentials” as the Grant Type.
Due to this legacy grant type, Westpac have been advised by our Security architecture to get Condeco to uplift the grant type to accept “Client credentials”. This issue impacts the following API functions.
- Condeco Visitor API
- SCIM API
1
vote
Alex White
shared this idea