Here’s the comprehensive solution for your API scope permission issues after upgrading to R1 2024:
1. OAuth2 Scope Naming Conventions
Workday R1 2024 introduced versioned API scopes to support parallel API versions. The naming convention changed from flat scope names to version-specific scopes:
Old (R2 2023 and earlier):
- asset_management_read
- asset_management_write
- asset_management_admin
New (R1 2024):
- asset_management_read_v2
- asset_management_write_v2
- asset_management_admin_v2
- asset_management_depreciation_read_v2 (new granular scope)
- asset_management_lifecycle_read_v2 (new granular scope)
The versioned scopes align with REST API endpoint versions (/api/v2/assetManagement).
2. Version-Specific Scope Changes
R1 2024 made several breaking changes to Asset Management API scopes:
Deprecated Scopes (no longer valid):
- asset_management_read → Use asset_management_read_v2
- asset_management_write → Use asset_management_write_v2
New Granular Scopes (R1 2024 introduces fine-grained access):
- asset_management_depreciation_read_v2: Required for depreciation calculation endpoints
- asset_management_lifecycle_read_v2: Required for asset lifecycle status endpoints
- asset_management_attributes_write_v2: Required for updating asset attributes
Scope-to-Endpoint Mapping:
GET /api/v2/assetManagement/assets → Requires: asset_management_read_v2
GET /api/v2/assetManagement/depreciation → Requires: asset_management_depreciation_read_v2
PUT /api/v2/assetManagement/assets/{id} → Requires: asset_management_write_v2
POST /api/v2/assetManagement/lifecycle → Requires: asset_management_lifecycle_read_v2
3. Token Claim Validation
Workday’s API gateway in R1 2024 performs strict token claim validation:
Validation Process:
// Pseudocode - API gateway validation flow:
1. Extract OAuth2 token from Authorization header
2. Decode JWT and extract 'scope' claim
3. Match requested endpoint to required scope
4. Verify scope claim contains required versioned scope
5. If scope missing or wrong version: Return 403 insufficient_scope
6. If scope present: Proceed to ISU permission validation
Token Claim Structure (R1 2024):
{
"iss": "https://wd2-impl.workday.com",
"sub": "ISU_ASSET_API_CLIENT",
"scope": "asset_management_read_v2 asset_management_depreciation_read_v2",
"aud": "workday_api",
"exp": 1735567890
}
4. API Gateway Scope Enforcement
The API gateway enforces scope requirements at multiple levels:
Update OAuth2 Client Registration:
- Navigate to: View Integration System > [Your API Client]
- Select “Edit Integration Security”
- In OAuth2 Configuration section:
- Remove deprecated scopes: asset_management_read
- Add required v2 scopes:
- asset_management_read_v2
- asset_management_depreciation_read_v2 (if accessing depreciation data)
- asset_management_write_v2 (if updating assets)
- Save changes
Update Token Request:
Modify your OAuth2 token request to include new scopes:
POST https://wd2-impl.workday.com/ccx/oauth2/token
Content-Type: application/x-www-form-urlencoded
grant_type=client_credentials
&client_id=ASSET_API_CLIENT
&client_secret=[secret]
&scope=asset_management_read_v2 asset_management_depreciation_read_v2
Update Integration System User Permissions:
The OAuth2 scope must align with ISU functional permissions. In R1 2024, Asset Management permissions are more granular:
- Navigate to: Edit Integration System User > [Your ISU]
- Update Domain Permissions:
- Domain: Asset Management
- Permissions:
- View Assets (maps to asset_management_read_v2)
- View Asset Depreciation (maps to asset_management_depreciation_read_v2)
- Modify Assets (maps to asset_management_write_v2)
- Add Business Process Permissions:
- Business Process: Manage Asset Lifecycle
- Permission: View (if using lifecycle endpoints)
Scope-to-Permission Mapping:
- asset_management_read_v2 → ISU needs “View Assets” domain permission
- asset_management_depreciation_read_v2 → ISU needs “View Asset Depreciation” permission
- asset_management_write_v2 → ISU needs “Modify Assets” domain permission
Verification Steps:
-
Verify API Client Scopes:
- View your API client registration
- Confirm v2 scopes are listed in OAuth2 configuration
-
Test Token Request:
curl -X POST https://wd2-impl.workday.com/ccx/oauth2/token \
-d "grant_type=client_credentials" \
-d "client_id=ASSET_API_CLIENT" \
-d "client_secret=[secret]" \
-d "scope=asset_management_read_v2"
-
Decode Token Claims:
- Copy access_token from response
- Decode at jwt.io
- Verify ‘scope’ claim contains “asset_management_read_v2”
-
Test API Call:
curl -X GET https://wd2-impl.workday.com/api/v2/assetManagement/assets \
-H "Authorization: Bearer [access_token]"
Migration Checklist:
- ✓ Update API client registration with v2 scopes
- ✓ Update ISU permissions to match v2 permission model
- ✓ Modify token request to include v2 scopes
- ✓ Update API endpoint URLs to use /api/v2/ if still using v1
- ✓ Test token generation and verify scope claims
- ✓ Test API calls to each required endpoint
- ✓ Update API documentation with new scope requirements
- ✓ Monitor API gateway logs for scope validation errors
Common Pitfalls:
- Requesting v2 scopes but calling v1 API endpoints (scope mismatch)
- Updating OAuth2 client scopes but not updating ISU permissions
- Including v2 scopes in client registration but not in token request
- Using generic asset_management_read_v2 for depreciation endpoints (need specific depreciation scope)
Expected Outcome:
After implementing these changes, your OAuth2 tokens will contain the correct v2 scopes, API gateway will validate them successfully, and your asset management integration will retrieve data without 403 errors. Your depreciation reporting will resume with proper access to both asset details and depreciation calculation endpoints in R1 2024.
This draft is based on general Workday knowledge. It has not been verified against your specific version and environment. Practitioners: verify the steps and share your experience below.