Skip to content

Commit 8fc2353

Browse files
committed
docs: add Asgardeo provider guide
1 parent 4642574 commit 8fc2353

2 files changed

Lines changed: 102 additions & 0 deletions

File tree

‎docs/provider-guides/asgardeo.mdx‎

Lines changed: 101 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,101 @@
1+
---
2+
sidebar_position: 3
3+
sidebar_label: Asgardeo
4+
---
5+
6+
# Asgardeo
7+
8+
[Asgardeo](https://wso2.com/asgardeo) is a cloud-native identity as a service (IDaaS) platform that supports OAuth 2.0 and OpenID Connect (OIDC), providing robust identity and access management for modern applications.
9+
10+
:::note
11+
If you don't have an Asgardeo account, you can [sign up for free](https://asgardeo.io).
12+
:::
13+
14+
## Get issuer URL {#get-issuer-url}
15+
16+
You can find the issuer URL in the Asgardeo Console:
17+
18+
1. Log in to the [Asgardeo Console](https://console.asgardeo.io) and select your organization
19+
2. Navigate to the created application and open the **Info** tab
20+
3. The **Issuer** field will be displayed there
21+
22+
The issuer URL should look like:
23+
24+
```
25+
https://api.asgardeo.io/t/<your-organization-name>/oauth2/token
26+
```
27+
28+
You can also discover this endpoint dynamically via the [OIDC discovery endpoint](https://wso2.com/asgardeo/docs/guides/authentication/oidc/discover-oidc-configs).
29+
30+
## Create API resource and scopes {#create-api-resource-and-scopes}
31+
32+
Asgardeo supports Role-Based Access Control (RBAC) and fine-grained authorization using API resources and scopes.
33+
34+
1. Log in to the [Asgardeo Console](https://console.asgardeo.io) and select your organization
35+
2. Navigate to **API Authorization** in the left menu
36+
3. Click **New API Resource** and fill in the details:
37+
- **Identifier**: Your MCP server URL, e.g., `http://localhost:3001/`
38+
- **Display Name**: e.g., "Todo Manager"
39+
4. Add the scopes your MCP server needs, e.g.:
40+
- `create:todos`: "Create new todo items"
41+
- `read:todos`: "Read all todo items"
42+
- `delete:todos`: "Delete any todo item"
43+
5. Click **Create**
44+
45+
The scopes will be included in the JWT access token's `scope` claim as a space-separated string.
46+
47+
## Create roles {#create-roles}
48+
49+
Roles make it easier to manage permissions for groups of users:
50+
51+
1. Navigate to **User Management > Roles** in the left menu
52+
2. Click **New Role**
53+
3. Create roles with appropriate scopes, e.g.:
54+
- **Admin**: Assign all scopes (`create:todos`, `read:todos`, `delete:todos`)
55+
- **User**: Assign limited scopes (e.g., only `create:todos`)
56+
4. For each role, select the scopes from your API resource
57+
58+
Alternatively, you can configure roles at the application level:
59+
60+
1. Navigate to **Applications** and select your application
61+
2. Go to the **Roles** tab
62+
3. Select "Application Role" as the audience type
63+
4. Create and configure roles with their respective scope assignments
64+
65+
## Assign roles to users {#assign-roles-to-users}
66+
67+
1. Navigate to **User Management > Roles**
68+
2. Select a role (e.g., "Admin" or "User")
69+
3. Go to the **Users** tab
70+
4. Click **Assign User** and select the users to assign to this role
71+
72+
## Retrieving user identity {#retrieving-user-identity}
73+
74+
User information is encoded inside the ID token returned along with the access token. But as an OIDC provider, Asgardeo exposes a [UserInfo endpoint](https://wso2.com/asgardeo/docs/guides/authentication/oidc/request-user-info/) that allows applications to retrieve claims about the authenticated user in the payload.
75+
76+
To fetch an access token that can be used to access the userinfo endpoint, at least two scopes are required: `openid` and `profile`.
77+
78+
## Register MCP client {#register-mcp-client}
79+
80+
While Asgardeo supports dynamic client registration via a standard API, the endpoint is protected and requires an access token with the necessary permissions. You'll need to register the client manually through the Asgardeo Console.
81+
82+
### Register a client for VS Code
83+
84+
1. Log in to the [Asgardeo Console](https://console.asgardeo.io) and select your organization
85+
2. Create a new application:
86+
- Go to **Applications** → **New Application**
87+
- Choose **Standard-Based Application** → **OAuth 2.0/OpenID Connect**
88+
- Enter an application name like `VS Code`
89+
- In the **Authorized Redirect URLs** field, add:
90+
- `http://127.0.0.1`
91+
- `https://vscode.dev/redirect`
92+
- Click **Create**
93+
3. Configure the protocol settings:
94+
- Under the **Protocol** tab:
95+
- Copy the **Client ID** for later use
96+
- Ensure switching to `JWT` for the `Token Type` in **Access Token** section
97+
- Click **Update**
98+
4. Configure API authorization (if using RBAC):
99+
- Go to the **API Authorization** tab
100+
- Authorize the API resource you created earlier
101+
- Select the scopes the application can request

‎sidebars.ts‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,7 @@ const sidebars: SidebarsConfig = {
3333
items: [
3434
'provider-guides/logto',
3535
'provider-guides/keycloak',
36+
'provider-guides/asgardeo',
3637
'provider-guides/generic',
3738
],
3839
},

0 commit comments

Comments
 (0)