API scope permissions insufficient for asset management module

We recently upgraded to Workday R1 2024 and our asset management integration started failing with 403 Forbidden errors. The API calls to retrieve asset data are being rejected with “insufficient scope” messages. We’re using OAuth2 with the same scopes that worked in our previous version (R2 2023).

The error response:


{
  "error": "insufficient_scope",
  "error_description": "Required scope not present in token",
  "required_scope": "asset_management_read_v2"
}

Our current token has scope “asset_management_read” but apparently R1 2024 requires a different scope naming convention. The OAuth2 scope naming changes between versions aren’t documented clearly, and we’re blocked from retrieving asset data for our depreciation reporting. Has anyone mapped out the version-specific scope changes for Asset Management APIs? We need to understand how token claim validation differs in R1 2024.

Here’s the comprehensive solution for your API scope permission issues after upgrading to R1 2024:

1. OAuth2 Scope Naming Conventions Workday R1 2024 introduced versioned API scopes to support parallel API versions. The naming convention changed from flat scope names to version-specific scopes:

Old (R2 2023 and earlier):

  • asset_management_read
  • asset_management_write
  • asset_management_admin

New (R1 2024):

  • asset_management_read_v2
  • asset_management_write_v2
  • asset_management_admin_v2
  • asset_management_depreciation_read_v2 (new granular scope)
  • asset_management_lifecycle_read_v2 (new granular scope)

The versioned scopes align with REST API endpoint versions (/api/v2/assetManagement).

2. Version-Specific Scope Changes R1 2024 made several breaking changes to Asset Management API scopes:

Deprecated Scopes (no longer valid):

  • asset_management_read → Use asset_management_read_v2
  • asset_management_write → Use asset_management_write_v2

New Granular Scopes (R1 2024 introduces fine-grained access):

  • asset_management_depreciation_read_v2: Required for depreciation calculation endpoints
  • asset_management_lifecycle_read_v2: Required for asset lifecycle status endpoints
  • asset_management_attributes_write_v2: Required for updating asset attributes

Scope-to-Endpoint Mapping:


GET /api/v2/assetManagement/assets → Requires: asset_management_read_v2
GET /api/v2/assetManagement/depreciation → Requires: asset_management_depreciation_read_v2
PUT /api/v2/assetManagement/assets/{id} → Requires: asset_management_write_v2
POST /api/v2/assetManagement/lifecycle → Requires: asset_management_lifecycle_read_v2

3. Token Claim Validation Workday’s API gateway in R1 2024 performs strict token claim validation:

Validation Process:


// Pseudocode - API gateway validation flow:
1. Extract OAuth2 token from Authorization header
2. Decode JWT and extract 'scope' claim
3. Match requested endpoint to required scope
4. Verify scope claim contains required versioned scope
5. If scope missing or wrong version: Return 403 insufficient_scope
6. If scope present: Proceed to ISU permission validation

Token Claim Structure (R1 2024):

{
  "iss": "https://wd2-impl.workday.com",
  "sub": "ISU_ASSET_API_CLIENT",
  "scope": "asset_management_read_v2 asset_management_depreciation_read_v2",
  "aud": "workday_api",
  "exp": 1735567890
}

4. API Gateway Scope Enforcement The API gateway enforces scope requirements at multiple levels:

Update OAuth2 Client Registration:

  1. Navigate to: View Integration System > [Your API Client]
  2. Select “Edit Integration Security”
  3. In OAuth2 Configuration section:
    • Remove deprecated scopes: asset_management_read
    • Add required v2 scopes:
      • asset_management_read_v2
      • asset_management_depreciation_read_v2 (if accessing depreciation data)
      • asset_management_write_v2 (if updating assets)
  4. Save changes

Update Token Request: Modify your OAuth2 token request to include new scopes:


POST https://wd2-impl.workday.com/ccx/oauth2/token
Content-Type: application/x-www-form-urlencoded

grant_type=client_credentials
&client_id=ASSET_API_CLIENT
&client_secret=[secret]
&scope=asset_management_read_v2 asset_management_depreciation_read_v2

Update Integration System User Permissions: The OAuth2 scope must align with ISU functional permissions. In R1 2024, Asset Management permissions are more granular:

  1. Navigate to: Edit Integration System User > [Your ISU]
  2. Update Domain Permissions:
    • Domain: Asset Management
    • Permissions:
      • View Assets (maps to asset_management_read_v2)
      • View Asset Depreciation (maps to asset_management_depreciation_read_v2)
      • Modify Assets (maps to asset_management_write_v2)
  3. Add Business Process Permissions:
    • Business Process: Manage Asset Lifecycle
    • Permission: View (if using lifecycle endpoints)

Scope-to-Permission Mapping:

  • asset_management_read_v2 → ISU needs “View Assets” domain permission
  • asset_management_depreciation_read_v2 → ISU needs “View Asset Depreciation” permission
  • asset_management_write_v2 → ISU needs “Modify Assets” domain permission

Verification Steps:

  1. Verify API Client Scopes:

    • View your API client registration
    • Confirm v2 scopes are listed in OAuth2 configuration
  2. Test Token Request:


curl -X POST https://wd2-impl.workday.com/ccx/oauth2/token \
  -d "grant_type=client_credentials" \
  -d "client_id=ASSET_API_CLIENT" \
  -d "client_secret=[secret]" \
  -d "scope=asset_management_read_v2"
  1. Decode Token Claims:

    • Copy access_token from response
    • Decode at jwt.io
    • Verify ‘scope’ claim contains “asset_management_read_v2”
  2. Test API Call:


curl -X GET https://wd2-impl.workday.com/api/v2/assetManagement/assets \
  -H "Authorization: Bearer [access_token]"

Migration Checklist:

  1. ✓ Update API client registration with v2 scopes
  2. ✓ Update ISU permissions to match v2 permission model
  3. ✓ Modify token request to include v2 scopes
  4. ✓ Update API endpoint URLs to use /api/v2/ if still using v1
  5. ✓ Test token generation and verify scope claims
  6. ✓ Test API calls to each required endpoint
  7. ✓ Update API documentation with new scope requirements
  8. ✓ Monitor API gateway logs for scope validation errors

Common Pitfalls:

  • Requesting v2 scopes but calling v1 API endpoints (scope mismatch)
  • Updating OAuth2 client scopes but not updating ISU permissions
  • Including v2 scopes in client registration but not in token request
  • Using generic asset_management_read_v2 for depreciation endpoints (need specific depreciation scope)

Expected Outcome: After implementing these changes, your OAuth2 tokens will contain the correct v2 scopes, API gateway will validate them successfully, and your asset management integration will retrieve data without 403 errors. Your depreciation reporting will resume with proper access to both asset details and depreciation calculation endpoints in R1 2024.


This draft is based on general Workday knowledge. It has not been verified against your specific version and environment. Practitioners: verify the steps and share your experience below.

Workday introduced versioned API scopes in R1 2024 to support backward compatibility while enabling new API features. The old scope names like “asset_management_read” are deprecated. You need to update your OAuth2 client configuration to request the v2 scopes. Check your API client registration in Workday and update the scope list to include “asset_management_read_v2” and “asset_management_write_v2” if you need write access.

I ran into this last month. The scope versioning is tied to the REST API version endpoints. If you’re calling /api/v1/assetManagement, you need v1 scopes. But R1 2024 introduced /api/v2/assetManagement with enhanced features, requiring v2 scopes. The confusing part is that R1 2024 deprecated some v1 endpoints entirely, forcing you to use v2. Your API gateway is enforcing v2 scope requirements because you’re probably hitting a v2-only endpoint without realizing it.

That makes sense. We didn’t explicitly change our endpoint URLs, so maybe Workday redirected our v1 calls to v2 endpoints after the upgrade? How do we update the OAuth2 client scopes? Do we need to re-register our API client, or can we modify the existing registration?

You can modify the existing API client registration. Go to View Integration System > [Your API Client] > Edit Integration Security. In the OAuth2 section, you’ll see the list of assigned scopes. Add the new v2 scopes there. However, make sure your Integration System User has the corresponding functional permissions. The scope is just the OAuth2 claim - the actual authorization still depends on the ISU’s domain permissions. If your ISU doesn’t have Asset Management v2 permissions, even with the correct scope, calls will fail with 403.

Confirmed this resolves the 403 errors we were seeing — updating our OAuth2 client registration in Workday Studio to use asset_management_read_v2 and asset_management_write_v2 scopes fixed the integration immediately.

David’s point about ISU permissions is crucial. The scope naming convention change isn’t just cosmetic - it reflects actual permission model changes in R1 2024. Asset Management v2 APIs have more granular permissions like “View Asset Details”, “View Asset Depreciation”, “Modify Asset Attributes” instead of the old monolithic “Asset Management” domain. You need to audit your ISU’s permissions and map them to the new v2 permission structure.

Here’s a practical tip: decode your current OAuth2 token to see what scopes are actually present. Use jwt.io or similar tool to inspect the token claims. Compare that against what the API gateway is expecting (shown in your error message). This will tell you if the problem is in your token request (missing scope in client registration) or in the token itself (scope granted but not included in token). Sometimes the scope is registered but not actually requested in the OAuth2 token endpoint call.