REST API authentication fails when posting intercompany journal entries

We’re hitting a wall with our Workday REST API integration for intercompany journal entries. Getting consistent 401 Unauthorized errors when posting journals between our US and EMEA entities. The OAuth2 token generation works fine for single-tenant operations, but fails on cross-company postings.

Our setup uses a service account with Financial Accounting permissions, and we’re following the standard token flow. The error happens specifically when the journal entry spans multiple companies - single company entries work perfectly.


POST /financials/v1/journalEntries
Authorization: Bearer eyJhbG...
Content-Type: application/json
Response: 401 {"error":"insufficient_scope"}

The token validation seems to fail at the API gateway level before even reaching the Workday tenant. We’ve checked the OAuth2 scopes in our integration system security configuration, but the multi-tenant aspect isn’t clearly documented. Has anyone dealt with API gateway header requirements for intercompany transactions? This is blocking our month-end close process.

Let me provide a complete solution that addresses all three critical areas: OAuth2 scope configuration, multi-tenant token validation, and API gateway requirements.

OAuth2 Scope and Claims Setup: Your integration system needs these specific scopes in the security configuration:

  • Financial_Accounting (base scope)
  • Intercompany_Accounting (cross-company operations)
  • Multi_Company_API_Access (critical for R1 2023)

In Domain Security Policies, enable “Allow API Access Across Multiple Companies” for your integration system.

Multi-Tenant Token Validation: Modify your token request to include all companies:


POST /oauth2/token
company_scope=US_ENTITY,EMEA_ENTITY
grant_type=client_credentials

This generates a token with proper audience claims for both tenants. The key is the company_scope parameter - without it, you get a single-tenant token that fails validation.

API Gateway Header Requirements: Your journal entry POST must include:


POST /financials/v1/journalEntries
Authorization: Bearer {multi_tenant_token}
Workday-Company-Context: US_ENTITY,EMEA_ENTITY
Content-Type: application/json

The Workday-Company-Context header (not X-Workday-Tenant-Context - that’s deprecated) tells the gateway which companies to validate against. Without this header, the gateway can’t match your token’s audience claims to the transaction companies.

Additional Configuration: In your integration system security group, verify:

  1. “View” and “Modify” permissions for Journal Entries in BOTH companies
  2. “Intercompany Accounting” functional area is enabled
  3. API gateway timeout is set to at least 60 seconds (intercompany validation takes longer)

After making these changes, regenerate your OAuth2 token. The 401 error should resolve. If you still see issues, check the Workday API logs (Setup > Integration > System > View Integration Events) for detailed validation failure messages. The logs will show exactly which claim or permission is missing.

One final note: if you’re using a reverse proxy or API management layer in front of Workday, ensure it’s not stripping the Workday-Company-Context header. We’ve seen several implementations where the proxy configuration removed custom headers, causing this exact authentication failure.


This draft is based on general Workday knowledge. It has not been verified against your specific version and environment. Practitioners: verify the steps and share your experience below.

I’ve seen this exact issue. The problem is that intercompany journal entries require additional OAuth2 claims that aren’t included in the standard Financial Accounting scope. You need to add the “Intercompany_Accounting” scope to your integration system security setup. Also check that your service account has permissions in BOTH companies involved in the transaction.

Thanks for the quick response. I added the Intercompany_Accounting scope to our integration system, but still getting the same 401 error. The service account does have cross-company access configured - we can query data from both entities successfully. It’s specifically the POST operation that fails. Could this be related to tenant-level token validation settings?

Check your token’s aud (audience) claim. For multi-tenant operations, Workday’s API gateway validates that the token audience matches ALL companies in the transaction. If your token is scoped to a single tenant identifier, it will reject cross-company operations. You might need to request a token with a broader audience claim or use the tenant federation endpoint.

We ran into this last quarter during our consolidation setup. The issue was that our API gateway headers weren’t including the X-Workday-Tenant-Context header for cross-company operations. This header tells the gateway which companies are involved in the transaction so it can validate permissions correctly. Without it, the gateway defaults to single-tenant validation and rejects the request. Make sure you’re passing all company IDs in that header as a comma-separated list.

Sara, that’s interesting about the X-Workday-Tenant-Context header. I don’t see that documented anywhere in the R1 2023 API reference. Is this a custom header implementation or part of the standard gateway configuration? Can you share an example of how you’re constructing that header value?

The header Sara mentioned is actually part of the extended API gateway features, but there’s a simpler approach. For intercompany journals, you need to ensure your OAuth2 token request includes the company parameter with all relevant company IDs. When you request the token, add company=US_ENTITY,EMEA_ENTITY to your token endpoint call. This generates a multi-tenant token that the gateway will accept for cross-company operations. Also verify your integration system has the API_Client_for_Multiple_Companies permission enabled in the security group configuration.

Tested this on Workday R1 2023 and enabling the Multi_Company_API_Access scope in Domain Security Policies resolved our intercompany journal entry OAuth2 failures immediately.