wso2 / wso2/docs-apim

Doc Feedback: JWT and grant type sections

Open
#4,866 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

API-M-4.0.0 Docs/Waiting on SME Severity/Critical Type/Improvement Type/Question
Dominant language
CSS
Stars
99
Forks
708
Avg merge
1d 7h
Merged PRs (30d)
22

Description

Hi,

In API Manager Documentation 4.0.0 when you're describing Grant Types (for example password grant: https://apim.docs.wso2.com/en/latest/design/api-security/oauth2/grant-types/password-grant/) there is an example of a response from a token request:

image

This token is a hash, but when you're using WSO2 Api Manager, by default the response is a JWT:

image

In https://apim.docs.wso2.com/en/latest/design/api-security/api-authentication/secure-apis-using-oauth2-tokens/ there is a section that says:

image

So, any access token will be JWT? Is an error on the grant type section? Or can we change this behaviour?

Many thanks!!!!!!

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the Grant Types/password grant page and the Secure APIs Using OAuth2 Tokens page linked in the issue; compare their token examples and statements about default access-token formats. Confirm the intended API Manager behavior, then make the affected documentation consistent and ensure it clearly explains whether JWT access tokens are expected or configurable.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, documentation, security
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.