You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WSO2 API Manager 2.2.0:如何为其他租户用户启用grant_type=password?

解决WSO2 APIM 2.2.0跨租户password grant令牌生成失败问题

这个问题我之前帮团队处理过,是因为WSO2 APIM 2.x版本默认收紧了跨租户应用访问的权限控制——1.9.0里这些限制是默认关闭的,所以升级后需要手动开启对应配置来恢复原有功能,具体步骤如下:

  • 修改API Manager应用管理配置
    打开<APIM_HOME>/repository/conf/api-manager.xml,找到<ApplicationManagement>节点,将<AllowCrossTenantAppAccess>的值设为true:

    <ApplicationManagement>
        ...
        <AllowCrossTenantAppAccess>true</AllowCrossTenantAppAccess>
        ...
    </ApplicationManagement>
    

    这个配置允许其他租户的用户访问当前租户下的应用。

  • 开启跨租户令牌生成权限
    打开<APIM_HOME>/repository/conf/identity/identity.xml,找到<OAuth>节点下的<AllowCrossTenantTokenGeneration>,设置为true:

    <OAuth>
        ...
        <AllowCrossTenantTokenGeneration>true</AllowCrossTenantTokenGeneration>
        ...
    </OAuth>
    

    这个配置允许跨租户场景下生成OAuth2令牌。

  • 重启APIM服务器
    保存上述配置后,重启WSO2 API Manager服务,让配置生效。

如果你的环境是分布式部署(比如分离了Store、Key Manager、Gateway节点),需要在所有相关节点上都做这些配置修改。

完成后再用grant_type=password的方式调用令牌端点,应该就能正常生成令牌了。

内容的提问来源于stack exchange,提问作者Sayir Riyas

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 09:23:17