# OAuth2 Token works with /idp/oauth2/userinfo but WebConsole REST API returns /openiam-ui-static/401

**URL:** <https://community.openiam.com/t/oauth2-token-works-with-idp-oauth2-userinfo-but-webconsole-rest-api-returns-openiam-ui-static-401/227>\
**Category:** Getting Started with OpenIAM\
**Created:** [June 2, 2026, 9:41am UTC](https://community.openiam.com/t/oauth2-token-works-with-idp-oauth2-userinfo-but-webconsole-rest-api-returns-openiam-ui-static-401/227 "2026-06-02T09:41:30Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Luca](https://avatars.discourse-cdn.com/v4/letter/l/51bf81/32.png) [@Luca](https://community.openiam.com/u/Luca)\
**Post date:** [June 2, 2026, 9:41am UTC](https://community.openiam.com/t/oauth2-token-works-with-idp-oauth2-userinfo-but-webconsole-rest-api-returns-openiam-ui-static-401/227/1 "2026-06-02T09:41:30Z")

</div>

Hello,

I am currently evaluating the OpenIAM REST API and OAuth2 integration on OpenIAM 4.2.1.13

I created an OAuth Client according to the official documentation:

- Create Auth Provider

- Granting Authorization

- API Call Examples

OAuth Client configuration:

- Grant Type: Client Credentials (also tested with Authorization Code)

- Auth Type: Basic HTTP

- Scopes:

The OAuth flow itself appears to work correctly.

### Client Credentials Flow

Request:

```auto
POST /idp/oauth2/token
grant_type=client_credentials

```

Response:

```auto
{
  "access_token": "...",
  "token_type": "Bearer"
}

```

Token validation:

```auto
GET /idp/oauth2/userinfo
Authorization: Bearer <token>

```

Response:

```auto
{
  "sub": "0001",
  "user_name": "system"
}

```

### Authorization Code Flow

Request:

```auto
GET /idp/oauth2/userinfo
Authorization: Bearer <token>

```

Response:

```auto
{
  "sub": "3000",
  "user_name": "sysadmin"
}

```

The token is also correctly stored in the `OAUTH_TOKEN` table and associated with the expected user.

### Problem

Any call to the WebConsole REST API fails.

Example:

```auto
POST /webconsole/rest/api/users/search?deepCopy=true
Authorization: Bearer <token>
Content-Type: application/json

```

Body:

```auto
{
  "from": 0,
  "size": 20,
  "principal": "sysadmin"
}

```

Response:

```auto
{
  "timestamp": ...,
  "status": 404,
  "error": "Not Found",
  "path": "/openiam-ui-static/401"
}

```

This appears to be an internal 401 Unauthorized that is redirected to `/openiam-ui-static/401`, which does not exist and therefore results in a 404.

### Question

Since `/idp/oauth2/userinfo` successfully validates the token and resolves the correct user, OAuth itself seems to be working.

Are additional configuration steps required to authorize OAuth clients against:

```auto
/webconsole/rest/api/*

```

or

```auto
/selfservice/rest/api/*

```

endpoints?

Is there a specific API role, resource mapping, scope configuration, or OAuth provider setting required beyond what is described in the API documentation?

Any guidance would be appreciated.

---

<div class="post-metadata">

**Author:** ![ameet\_shah](https://yyz2.discourse-cdn.com/flex010/user_avatar/community.openiam.com/ameet_shah/32/17_2.png) [@ameet\_shah](https://community.openiam.com/u/ameet_shah)\
**Post date:** [June 2, 2026, 9:17pm UTC](https://community.openiam.com/t/oauth2-token-works-with-idp-oauth2-userinfo-but-webconsole-rest-api-returns-openiam-ui-static-401/227/2 "2026-06-02T21:17:00Z")

</div>

Hello @Luca,

Thanks for your questions. I’ve reached out internally and will have answers for you shortly.

Thanks,

Ameet

---

<div class="post-metadata">

**Author:** ![ameet\_shah](https://yyz2.discourse-cdn.com/flex010/user_avatar/community.openiam.com/ameet_shah/32/17_2.png) [@ameet\_shah](https://community.openiam.com/u/ameet_shah)\
**Post date:** [June 5, 2026, 5:16pm UTC](https://community.openiam.com/t/oauth2-token-works-with-idp-oauth2-userinfo-but-webconsole-rest-api-returns-openiam-ui-static-401/227/3 "2026-06-05T17:16:32Z")

</div>

Hello @Luca ,

Please add the OAUTH scope-user\_name to your OAuth Provider configuration. This should help ensure that the user\_name claim is included in the token introspection response, allowing the reverse proxy to correctly identify the user and complete the authentication flow.

Thanks.

---

<div class="post-metadata">

**Author:** ![Luca](https://avatars.discourse-cdn.com/v4/letter/l/51bf81/32.png) [@Luca](https://community.openiam.com/u/Luca)\
**Post date:** [June 9, 2026, 8:19am UTC](https://community.openiam.com/t/oauth2-token-works-with-idp-oauth2-userinfo-but-webconsole-rest-api-returns-openiam-ui-static-401/227/4 "2026-06-09T08:19:29Z")

</div>

Hello Ameet,

Thank you for your response.

I would like to clarify that the `OAUTH_user_name` scope was already present in the OAuth Provider configuration before I opened this thread.

Current scopes are:

- MTK-/webconsole/\*

- Main-Taunus-Kreis-/webconsole/\*

- OAUTH\_user\_name

 ![OpenIamClient](https://canada1.discourse-cdn.com/flex010/uploads/openiam_community/original/1X/822fc0c7b11ef8b49f90b24602ca0a848f81ccd7.png)

To verify this, I generated completely new access tokens and repeated all tests.

### Token validation

```auto
GET /idp/oauth2/userinfo
Authorization: Bearer CTQRoDfeGBOM01R.7UBCV3HTZlZE4rnWHMQ4_y.HwFu3nyYSdagy7oLtwhKnC2RtdOXLWXmX0A8qNO

```

Response:

```auto
{
  "sub":"3000",
  "user_name":"sysadmin",
  "auth_time":1780992128
}

```

This confirms that:

- OAuth authentication works

- the token is valid

- the token resolves to the correct user

- the `user_name` claim is already present

### API tests

Using the exact same access token:

```auto
GET /webconsole/rest/api/profile

```

```auto
GET /selfservice/rest/api/profile

```

```auto
POST /webconsole/rest/api/users/search

```

All requests return:

```auto
{
  "status":404,
  "error":"Not Found",
  "path":"/openiam-ui-static/401"
}

```

The same behavior occurs with:

- Authorization Code Flow (`sysadmin`)

- Client Credentials Flow (`system`)

In both cases `/idp/oauth2/userinfo` succeeds, while all `/webconsole/rest/api/*` and `/selfservice/rest/api/*` requests fail.

Is there any additional configuration required to allow OAuth Bearer Tokens to access the WebConsole or Selfservice REST APIs?

Thank you.

---

<div class="post-metadata">

**Author:** ![ameet\_shah](https://yyz2.discourse-cdn.com/flex010/user_avatar/community.openiam.com/ameet_shah/32/17_2.png) [@ameet\_shah](https://community.openiam.com/u/ameet_shah)\
**Post date:** [June 16, 2026, 9:10pm UTC](https://community.openiam.com/t/oauth2-token-works-with-idp-oauth2-userinfo-but-webconsole-rest-api-returns-openiam-ui-static-401/227/5 "2026-06-16T21:10:14Z")

</div>

Hello @Luca,

For this issue, the OAuth client must have **`/webconsole/rest/api/*`** configured as a default scope. Without this scope, calls to the OpenIAM REST APIs may return a 401 Unauthorized response even though the token works successfully against the UserInfo endpoint.

---

<div class="post-metadata">

**Author:** ![Luca](https://avatars.discourse-cdn.com/v4/letter/l/51bf81/32.png) [@Luca](https://community.openiam.com/u/Luca)\
**Post date:** [June 18, 2026, 6:47am UTC](https://community.openiam.com/t/oauth2-token-works-with-idp-oauth2-userinfo-but-webconsole-rest-api-returns-openiam-ui-static-401/227/6 "2026-06-18T06:47:39Z")

</div>

> [@ameet\_shah](#):
>
> /webconsole/rest/api/\*

That resolved my problem! Thank you for your support.

---

<div class="post-metadata">

**Author:** ![ameet\_shah](https://yyz2.discourse-cdn.com/flex010/user_avatar/community.openiam.com/ameet_shah/32/17_2.png) [@ameet\_shah](https://community.openiam.com/u/ameet_shah)\
**Post date:** [June 18, 2026, 1:04pm UTC](https://community.openiam.com/t/oauth2-token-works-with-idp-oauth2-userinfo-but-webconsole-rest-api-returns-openiam-ui-static-401/227/7 "2026-06-18T13:04:14Z")

</div>

You are very welcome, @Luca. Please let us know if we can help with anything else.
