WSO2 IS 5.9.0环境下如何为角色添加权限?附SCIM2 API创建组信息
Hey there! Let's figure out how to add permissions to the s2ic group you created via SCIM2 in WSO2 IS 5.9.0. Since SCIM2 focuses on core identity data (users, groups) and doesn't natively handle permission management, we'll use WSO2's built-in admin tools to get this done. Here are the most straightforward approaches:
This is the simplest way if you don't need automation:
- Log into the WSO2 IS management console at
https://localhost:9443/carbonusing your admin credentials. - Navigate to Main > Identity > Roles and Permissions > List Roles.
- Locate the
s2icgroup (in WSO2 IS, SCIM groups map directly to system roles) and click the Permissions link next to it. - In the permission management screen, check the boxes for all permissions you want to assign (e.g., login access, application-specific permissions, resource permissions).
- Hit Update to save your changes.
Perfect for scripts or automated workflows:
Step 1: Get an Admin Access Token
Send a POST request to https://localhost:9443/oauth2/token with form-data parameters:
grant_type: password username: admin password: admin client_id: admin client_secret: admin
Extract the access_token from the response—you'll need this for all subsequent API calls.
Step 2: Retrieve the Role UUID for Your SCIM Group
Send a GET request to https://localhost:9443/scim2/Groups?filter=displayName eq "s2ic" with the following header:
Authorization: Bearer <your-access-token>
Grab the id field from the response—this is the unique UUID of your s2ic role.
Step 3: Assign Permissions to the Role
Send a POST request to https://localhost:9443/api/identity/role/v1.0/roles/{role-uuid}/permissions (replace {role-uuid} with the UUID you retrieved). Use these headers:
Authorization: Bearer <your-access-token> Content-Type: application/json
Example request body (adjust permissions to match your needs):
{ "permissions": [ "/permission/admin/login", "/permission/application/MyCustomApp", "/permission/resource/MyAPI" ] }
Tip: To get a full list of valid permissions in your WSO2 IS instance, send a GET request to
https://localhost:9443/api/identity/permission/v1.0/permissionswith your admin access token.
If you prefer SOAP interfaces, you can use the RemoteAuthorizationManagerService's updateRolePermissions method. However, the REST API is more modern and easier to integrate into most workflows, so it's the recommended approach.
Key Notes
- In WSO2 IS 5.9.0, every SCIM group you create is automatically a system role—so all standard role permission operations apply to it.
- Make sure your admin account has sufficient privileges (the default
adminaccount has full access by default).
内容的提问来源于stack exchange,提问作者Anshul Walia

