DigitalBuzz Logo
OAuth Mule

OAUTH 2.0 IMPLEMENTATION USING MULE OAUTH2 PROVIDER

Vinay Kumar Theetla
Posted By
Vinay Kumar Theetla
Technical Guide
8 min read
OAuth 2.0 Implementation Using Mule OAuth2 Provider

In this tutorial I will demonstrate how can we create the Mule OAUTH 2.0 provider using CLIENT_CREDENTIALS as Grant Type and deploy the same on Mule Runtime and get the bearer token value and also I will demonstrate how to apply OAUTH 2.0 Access Token enforcement policy using Mule OAUTH 2.0 Provider and use the token value generated to authenticate the mule api.

OAuth 2.0 Overview

OAuth 2.0 Authorization Protocol

OAuth 2.0 is the industry-standard protocol for authorization. OAuth 2.0 focuses on client developer simplicity while providing specific authorization flows for web applications, desktop applications, mobile phones, and living room devices.

Mule OAuth 2.0 Provider

Mule OAuth 2.0 Provider is an OAuth 2.0 provider alternative developed by MuleSoft that can be used in any MuleSoft API Platform organization.

OAuth 2.0 Grant Types

OAuth 2.0 specifies the following grant type methods for requesting a token:

AUTHORIZATION_CODE

Used by server-side web applications where source code is not exposed and client secret can remain confidential.

IMPLICIT

Simplified authorization code flow historically used by browser-based single page applications.

RESOURCE_OWNER_PASSWORD_CREDENTIALS

Used when the user has a high degree of trust in the client, passing username and password directly.

CLIENT_CREDENTIALS

Used for machine-to-machine (M2M) server communication where the client authenticates using its own credentials (used in this tutorial).

1Create project in anypoint studio

Drag and drop create client operation from mule palette and complete the configuration for Oauth2 Provider Config( if you did not find create client operation please add OAUTH provider module from exchange)

Create Client operation from Mule palette & OAuth2 Provider Config
Figure 1: Mule Palette with OAuth Provider module and Create Client operation
Anypoint Studio Flow and OAuth2 Provider Configuration
Figure 2: Flow canvas with HTTP Listener and Create Client operation

2Configure Client Object Store

Configure the client object store to prevent any possible downtime of Mule OAuth 2.0 Provider due to errors when connecting to Anypoint Platform, the Mule OAuth client store caches each valid client application(client credentials) for which a token is requested.

Configuring the Client Object Store in Mule OAuth2 Provider Config
Figure 3: Client store configuration referencing the local Object Store
Client Object Store Global Configuration Parameters
Figure 4: Client Object Store settings & cache parameters

3Configure Grant Type and Token

Pass the supported grant types as CLIENT_CREDENTIALS, path as /token to get the token and configure the token object store to store the token value, you can configure the token TTL as per requirement, I have kept is as default value and refresh token strategy as No Refresh Token as Default value

Supported Grant Types CLIENT_CREDENTIALS, path /token, and Token Object Store
Figure 5: Token generator endpoint path `/token` and CLIENT_CREDENTIALS configuration

4Global elements configuration

Global elements configuration:

Global Elements Configuration Tab in Anypoint Studio
Figure 6: Global configuration elements for HTTP Listener and OAuth2 Provider

5Configure the details for Create Client

Configure the details for Create Client

Create Client Operation Properties and Expression Parameters
Figure 7: Setting Client ID, Client Secret, Client Name, and Authorized Grant Types

6Validate Token Operation

Now next step is to add operation to validate the token

Drag and drop the validate token operation from mule palette in same project

Validate Token Operation Dragged to Flow in Anypoint Studio
Figure 8: Adding Validate Token operation into the validation sub-flow

7Set the response in Set Payload

Set the response in Set Payload

Set Payload Transformer Configuration
Figure 9: Setting the response payload value for successful execution

8Deployment and API Protection

Deploy the application on Cloudhub OAUTH provider application successfully running, we will use in next part to get the access token

OAuth Provider Application Successfully Running on Cloudhub
Figure 10: Mule OAuth Provider deployed and running in Cloudhub Runtime Manager

Create one sample mule application Deploy the sample Mule Application on Cloudhub

Sample Mule Application Flow in Anypoint Studio
Figure 11: Sample API application flow to be secured with OAuth 2.0 policy
Sample Mule Application Running on Cloudhub
Figure 12: Sample target application running in Cloudhub
API Manager Applying OAuth 2.0 Access Token Enforcement Policy
Figure 13: Configuring OAuth 2.0 Access Token Enforcement Policy using Mule OAuth Provider

Now I will register the client as mentioned

Registering Client via Postman Request to Create Client Endpoint
Figure 14: Client Registration POST request in Postman

Next step is to get the OAUTH token

Obtaining Bearer Token via /token Endpoint with CLIENT_CREDENTIALS
Figure 15: Postman call to `/token` returning access_token and bearer token type

pass the token in Header to invoke the mule api created

Passing Bearer Token in Authorization Header
Figure 16: Setting Authorization: Bearer <token> header

Now I will test the mule application without passing any Oauth credentials and got the error as “Access token was not provided”

Testing without token returns 401 Access token was not provided
Figure 17: HTTP 401 Unauthorized — “Access token was not provided”

Now I will test the mule application with all required parameters

Testing with Bearer token succeeds with HTTP 200 OK and response payload
Figure 18: HTTP 200 OK — Successful authenticated response with token verification

We applied the policy and retrieve the data successfully

Conclusion

In this tutorial, we successfully built and deployed a custom Mule OAuth 2.0 Provider leveraging Anypoint Studio and Cloudhub runtime. By configuring client caching stores, CLIENT_CREDENTIALS grant flow, and token endpoints, we generated valid bearer tokens to enforce enterprise-grade security policies on downstream Mule APIs.

Quote

“Thank you for taking out time to read the above post. Hope you found it useful. In case of any questions, feel free to comment below. Also, if you are keen on knowing about a specific topic, happy to explore your recommendations as well.”

Vinay Kumar Theetla
About the Author

Vinay Kumar Theetla

Integration and API Security Specialist at DigitalBuzz Software, experienced in MuleSoft Anypoint Platform, Cloudhub architectures, OAuth 2.0 authentication, and enterprise API governance.

Share this article