This is a known configuration gap in TC 12.3 when combining OAuth2 with Service Management REST APIs in multi-tenant environments. Here’s the complete solution addressing all three critical areas:
OAuth2 Scope Mapping Configuration:
First, update your OAuth2 client registration to explicitly include Service Management scopes. In your authorization server configuration, add the custom scope definitions:
tc.service.read=Read access to Service Management
tc.service.write=Write access to Service Management
tc.service.admin=Admin access to Service Management
Ensure these scopes are added to your client’s allowed scope list in the OAuth2 provider configuration.
Multi-Tenant Token Validation:
The key issue is tenant context resolution. Your API gateway needs to extract tenant identification from the token (typically from a custom claim like ‘tenant_id’ or from the token’s audience claim) BEFORE performing scope validation. Configure your gateway’s authentication pipeline to:
- Extract tenant context from token claims
- Load tenant-specific scope mapping configuration
- Validate scopes against tenant-specific rules
- Apply tenant-specific permission mappings
In your gateway configuration file, add tenant-aware scope validation:
gateway.auth.tenant.claim=tenant_id
gateway.auth.tenant.scope.mapping.enabled=true
gateway.auth.scope.validation.order=tenant_context,scope_check
API Gateway Configuration:
Update your gateway’s endpoint-to-scope mapping to include Service Management operations. The gateway needs explicit rules mapping OAuth2 scopes to actual API endpoints. Add these mappings to your gateway configuration:
/api/v1/service-requests/** = tc.service.write
/api/v1/service-requests/*/approve = tc.service.admin
/api/v1/service-requests/query = tc.service.read
Also critical: ensure your token introspection endpoint returns all custom scopes. Many OAuth2 providers only return standard scopes in introspection responses unless explicitly configured. Update your authorization server’s introspection endpoint configuration to include custom scope attributes in the response.
Verification Steps:
- Test token generation and verify custom scopes appear in the JWT payload
- Call the introspection endpoint and confirm all scopes are returned
- Check gateway logs to verify tenant context is resolved before scope validation
- Test Service Management API calls with properly scoped tokens
After implementing these changes, restart both your authorization server and API gateway. The insufficient_scope error should resolve once the gateway properly maps tenant-specific scopes to Service Management endpoints. This configuration ensures OAuth2 tokens are validated with full awareness of both tenant context and module-specific scope requirements.
This draft is based on general Teamcenter knowledge. It has not been verified against your specific version and environment. Practitioners: verify the steps and share your experience below.