<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.appian.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>How to validate scope parameter in Web APIs</title><link>https://community.appian.com/discussions/f/integrations/34838/how-to-validate-scope-parameter-in-web-apis</link><description>Hi all, 
 We need to validate the scope parameter in Web APIs. I&amp;#39;ve seen in the documentation that with the Appian OAuth 2.0 client the scope parameter must either be blank or omitted entirely: 
 https://docs.appian.com/suite/help/24.1/Web_API_Authentication</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: How to validate scope parameter in Web APIs</title><link>https://community.appian.com/thread/134763?ContentTypeID=1</link><pubDate>Mon, 06 May 2024 13:00:51 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:800c5719-03fe-411c-821e-c2148e449dd8</guid><dc:creator>JJ Ca&amp;#241;as</dc:creator><description>&lt;p&gt;Ok, so I need to validate the scope within my Web API. Thanks!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: How to validate scope parameter in Web APIs</title><link>https://community.appian.com/thread/134689?ContentTypeID=1</link><pubDate>Fri, 03 May 2024 14:28:49 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:8df6d1e2-a004-4051-8761-296febdde2a2</guid><dc:creator>manishs0028</dc:creator><description>&lt;p&gt;&amp;nbsp;&lt;a href="/members/josejavierc0001"&gt;JJ Cañas&lt;/a&gt;&amp;nbsp;R&lt;span&gt;ecently in 24.1 release they mentioned how we can use&amp;nbsp;&lt;/span&gt;&lt;span&gt;OAuth 2.0.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;img style="max-height:240px;max-width:320px;" src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/18/pastedimage1714746385715v1.png" alt=" " /&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;you can potentially use a third-party OAuth 2.0 client for authentication, you would still need to ensure that scope validation is properly implemented within your Web API. This ensures that only authorized requests with the appropriate scope are allowed access to the resources.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>