Skip to content

API authorization for organizations

Asgardeo allows organizations to authorize user access to an application's API resources based on the API permissions, roles, and groups assigned to the users. See API authorization for more information.

API resources are created and authorized for applications on the organization (root). If the application consuming the API resources is shared with the organization, all application-specific configurations of API resources are inherited by the organization.

The relationship between terms

Prerequisites

You need to configure your API resources on the organization (root):

  1. Register an API resource
  2. Authorize the API resource to an app
  3. Create roles and associate to application