|
| 1 | +--- |
| 2 | +sidebar_position: 3 |
| 3 | +sidebar_label: Asgardeo |
| 4 | +--- |
| 5 | + |
| 6 | +# Asgardeo |
| 7 | + |
| 8 | +[Asgardeo](https://wso2.com/asgardeo) is a cloud-native identity as a service (IDaaS) platform that supports OAuth 2.0 and OpenID Connect (OIDC), providing robust identity and access management for modern applications. |
| 9 | + |
| 10 | +:::note |
| 11 | +If you don't have an Asgardeo account, you can [sign up for free](https://asgardeo.io). |
| 12 | +::: |
| 13 | + |
| 14 | +## Get issuer URL {#get-issuer-url} |
| 15 | + |
| 16 | +You can find the issuer URL in the Asgardeo Console: |
| 17 | + |
| 18 | +1. Log in to the [Asgardeo Console](https://console.asgardeo.io) and select your organization |
| 19 | +2. Navigate to the created application and open the **Info** tab |
| 20 | +3. The **Issuer** field will be displayed there |
| 21 | + |
| 22 | +The issuer URL should look like: |
| 23 | + |
| 24 | +``` |
| 25 | +https://api.asgardeo.io/t/<your-organization-name>/oauth2/token |
| 26 | +``` |
| 27 | + |
| 28 | +You can also discover this endpoint dynamically via the [OIDC discovery endpoint](https://wso2.com/asgardeo/docs/guides/authentication/oidc/discover-oidc-configs). |
| 29 | + |
| 30 | +## Create API resource and scopes {#create-api-resource-and-scopes} |
| 31 | + |
| 32 | +Asgardeo supports Role-Based Access Control (RBAC) and fine-grained authorization using API resources and scopes. |
| 33 | + |
| 34 | +1. Log in to the [Asgardeo Console](https://console.asgardeo.io) and select your organization |
| 35 | +2. Navigate to **API Authorization** in the left menu |
| 36 | +3. Click **New API Resource** and fill in the details: |
| 37 | + - **Identifier**: Your MCP server URL, e.g., `http://localhost:3001/` |
| 38 | + - **Display Name**: e.g., "Todo Manager" |
| 39 | +4. Add the scopes your MCP server needs, e.g.: |
| 40 | + - `create:todos`: "Create new todo items" |
| 41 | + - `read:todos`: "Read all todo items" |
| 42 | + - `delete:todos`: "Delete any todo item" |
| 43 | +5. Click **Create** |
| 44 | + |
| 45 | +The scopes will be included in the JWT access token's `scope` claim as a space-separated string. |
| 46 | + |
| 47 | +## Create roles {#create-roles} |
| 48 | + |
| 49 | +Roles make it easier to manage permissions for groups of users: |
| 50 | + |
| 51 | +1. Navigate to **User Management > Roles** in the left menu |
| 52 | +2. Click **New Role** |
| 53 | +3. Create roles with appropriate scopes, e.g.: |
| 54 | + - **Admin**: Assign all scopes (`create:todos`, `read:todos`, `delete:todos`) |
| 55 | + - **User**: Assign limited scopes (e.g., only `create:todos`) |
| 56 | +4. For each role, select the scopes from your API resource |
| 57 | + |
| 58 | +Alternatively, you can configure roles at the application level: |
| 59 | + |
| 60 | +1. Navigate to **Applications** and select your application |
| 61 | +2. Go to the **Roles** tab |
| 62 | +3. Select "Application Role" as the audience type |
| 63 | +4. Create and configure roles with their respective scope assignments |
| 64 | + |
| 65 | +## Assign roles to users {#assign-roles-to-users} |
| 66 | + |
| 67 | +1. Navigate to **User Management > Roles** |
| 68 | +2. Select a role (e.g., "Admin" or "User") |
| 69 | +3. Go to the **Users** tab |
| 70 | +4. Click **Assign User** and select the users to assign to this role |
| 71 | + |
| 72 | +## Retrieving user identity {#retrieving-user-identity} |
| 73 | + |
| 74 | +User information is encoded inside the ID token returned along with the access token. But as an OIDC provider, Asgardeo exposes a [UserInfo endpoint](https://wso2.com/asgardeo/docs/guides/authentication/oidc/request-user-info/) that allows applications to retrieve claims about the authenticated user in the payload. |
| 75 | + |
| 76 | +To fetch an access token that can be used to access the userinfo endpoint, at least two scopes are required: `openid` and `profile`. |
| 77 | + |
| 78 | +## Register MCP client {#register-mcp-client} |
| 79 | + |
| 80 | +While Asgardeo supports dynamic client registration via a standard API, the endpoint is protected and requires an access token with the necessary permissions. You'll need to register the client manually through the Asgardeo Console. |
| 81 | + |
| 82 | +### Register a client for VS Code |
| 83 | + |
| 84 | +1. Log in to the [Asgardeo Console](https://console.asgardeo.io) and select your organization |
| 85 | +2. Create a new application: |
| 86 | + - Go to **Applications** → **New Application** |
| 87 | + - Choose **Standard-Based Application** → **OAuth 2.0/OpenID Connect** |
| 88 | + - Enter an application name like `VS Code` |
| 89 | + - In the **Authorized Redirect URLs** field, add: |
| 90 | + - `http://127.0.0.1` |
| 91 | + - `https://vscode.dev/redirect` |
| 92 | + - Click **Create** |
| 93 | +3. Configure the protocol settings: |
| 94 | + - Under the **Protocol** tab: |
| 95 | + - Copy the **Client ID** for later use |
| 96 | + - Ensure switching to `JWT` for the `Token Type` in **Access Token** section |
| 97 | + - Click **Update** |
| 98 | +4. Configure API authorization (if using RBAC): |
| 99 | + - Go to the **API Authorization** tab |
| 100 | + - Authorize the API resource you created earlier |
| 101 | + - Select the scopes the application can request |
0 commit comments