
Announcements
Hello,
Is there a way to create a OAuth2 authorization connector without providing client_secret. The field is mandatory and if I provide a dummy value the connection "looks" successful but does not include Authorization in the header.
Our Oauth2 is set up for implicit grant and the work flow works fine in postman where I can just leave the field Client Secret blank.
Thanks
Hello x001nx
We understand that you would like to use implicit grant authorization in Custom connector
https://datatracker.ietf.org/doc/html/rfc6749#section-1.3.2
Note that only Authorization Code Grant flows and On-Behalf-Of flows support refresh tokens. Implicit Grants and Client Credentials Grants do not support refresh tokens, so may not be used to authenticate Custom Connectors.
Official Doc Reference:
https://support.microsoft.com/en-us/topic/verifying-oauth-configuration-for-custom-connectors-ceadbd1d-5a44-5615-208b-029f7ffe6107