I had almost the exact same issue last month. Here’s what fixed it - you need to check THREE specific areas where OAuth2 configuration can break:
1. OAuth2 Client Credentials Configuration:
Verify in your OAuth2 provider that the client has been granted BOTH scopes explicitly. In ICS 2021, go to Security Console > OAuth2 Clients > [Your Client] > Allowed Scopes. You should see both ‘inventory.read’ and ‘inventory.write’ checked. The system requires read permission to validate the inventory location exists before allowing writes.
2. API Gateway Authorization Mapping:
The gateway needs explicit permission mapping. Navigate to API Gateway Admin > Security Policies > Scope Mappings. Create or verify these mappings:
inventory.write -> INV_TRANSACTION_CREATE
inventory.write -> INV_TRANSACTION_UPDATE
inventory.read -> INV_TRANSACTION_READ
3. User Role and Backend Permissions:
This is the part most people miss - even with correct OAuth2 scopes, the service account user must have the actual ICS security roles assigned. Go to User Management > Service Accounts > [Your Service Account] and verify these roles are assigned:
- Inventory Transaction Manager
- Inventory Data Reader
The 401 error with ‘insufficient_scope’ usually means step 2 is misconfigured. The API Gateway is successfully validating your token but can’t map the OAuth2 scope to the required backend permission. After fixing the scope mappings, restart the API Gateway service to clear any cached authorization policies.
One more thing - if you’re posting transactions with specific warehouse or location codes, make sure your service account has data-level security permissions for those locations. ICS 2021 enforces location-based access control even through APIs, so a valid token with correct scopes can still fail if the user doesn’t have access to the specific inventory location in the transaction payload.
Test your fix with a simple curl command:
curl -X POST https://your-gateway/api/inventory/transactions \
-H "Authorization: Bearer YOUR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"location":"WH01","item":"ITEM001","quantity":10}'
If this works, your OAuth2 and gateway configuration is correct and any remaining issues are likely data-level permissions.
This draft is based on general Infor CloudSuite knowledge. It has not been verified against your specific version and environment. Practitioners: verify the steps and share your experience below.