---
title: How to Beef Up Your Security Using OAuth2 External Provider In Mule
description: A how-to guide on applying OAuth2 policy, using external provider, for managing clients in Anypoint Platform.
image: https://blog.avenuecode.com/hubfs/matt-artz-353284.jpg
---

[AvenueCode.com](https://avenuecode.com) [News](https://avenuecode.com/news) [Contact](https://avenuecode.com/contact)

[![Avenue Code Snippets Logo](https://blog.avenuecode.com/hubfs/Avenue%20Code%20New%20Logos%20-%202023/AC-Snippets---Black.png)](https://blog.avenuecode.com/?hsLang=en-us) *menu*

- Technology
  
  [Cloud](https://blog.avenuecode.com/blog/topic/cloud?hsLang=en-us) [Delivery Infrastructure](https://blog.avenuecode.com/blog/topic/delivery-infrastructure?hsLang=en-us) [Web Experience](https://blog.avenuecode.com/blog/topic/web-experience?hsLang=en-us) [Agile Mindset](https://blog.avenuecode.com/blog/topic/agile-mindset?hsLang=en-us) [Quality First](https://blog.avenuecode.com/blog/topic/quality-first?hsLang=en-us)
  
  [Design](https://blog.avenuecode.com/blog/topic/design?hsLang=en-us) [Solution Architecture](https://blog.avenuecode.com/blog/topic/solution-architecture?hsLang=en-us) [Data & ML](https://blog.avenuecode.com/blog/topic/data-and-machine-learning?hsLang=en-us) [Mobile Experience](https://blog.avenuecode.com/blog/topic/mobile-experience?hsLang=en-us)
- [Whitepapers](https://blog.avenuecode.com/blog/topic/whitepapers?hsLang=en-us)
- [Spotlight](https://blog.avenuecode.com/blog/topic/spotlight?hsLang=en-us)
- [Extraordinary Women in Tech](https://blog.avenuecode.com/blog/topic/extraordinary-women-in-tech?hsLang=en-us)
- [Avenue Code Culture](https://blog.avenuecode.com/blog/topic/avenue-code-culture?hsLang=en-us)

- [Cloud](https://blog.avenuecode.com/blog/topic/cloud?hsLang=en-us)
- [Design](https://blog.avenuecode.com/blog/topic/design?hsLang=en-us)
- [Delivery Infrastructure](https://blog.avenuecode.com/blog/topic/delivery-infrastructure?hsLang=en-us)
- [Solution Architecture](https://blog.avenuecode.com/blog/topic/solution-architecture?hsLang=en-us)
- [Web Experience](https://blog.avenuecode.com/blog/topic/web-experience?hsLang=en-us)
- [Data & ML](https://blog.avenuecode.com/blog/topic/data-and-machine-learning?hsLang=en-us)
- [Agile Mindset](https://blog.avenuecode.com/blog/topic/agile-mindset?hsLang=en-us)
- [Mobile Experience](https://blog.avenuecode.com/blog/topic/mobile-experience?hsLang=en-us)
- [Quality First](https://blog.avenuecode.com/blog/topic/quality-first?hsLang=en-us)
- [Whitepapers](https://blog.avenuecode.com/blog/topic/whitepapers?hsLang=en-us)
- [Spotlight](https://blog.avenuecode.com/blog/topic/spotlight?hsLang=en-us)
- [Extraordinary Women in Tech](https://blog.avenuecode.com/blog/topic/extraordinary-women-in-tech?hsLang=en-us)
- [Avenue Code Culture](https://blog.avenuecode.com/blog/topic/avenue-code-culture?hsLang=en-us)

# [How to Beef Up Your Security Using OAuth2 External Provider In Mule](https://blog.avenuecode.com/using-oauth2-external-provider-in-mule)

- [Tweet](https://twitter.com/share)

*perm\_identity* [Anupam Gogoi](https://blog.avenuecode.com/using-oauth2-external-provider-in-mule/author/anupam-gogoi?hsLang=en-us)

*schedule* 10/3/17 4:00 PM

The main goal of choosing an Authentication Protocol is to avoid the heavy lifting on development side and to make it easy on the API users with regards to consuming APIs. With OAuth2, the user authenticates as a virtual user with the same credentials they normally use to access the web app. Many developers will find that with OAuth2, their application security will be strengthened and their workload lightened.

In this tutorial, I'm going to explain how to apply OAuth2 policy (using external provider) for managing clients in Anypoint Platform. OAuth2 is the industry-standard protocol for authorization. It enables applications to get limited access to resources on an HTTP service, such as Facebook, GitHub, Twitter, etc. The framework describes a number of grants for a client application to acquire an access token, which can be used to authenticate a request to an API endpoint.

OAuth2 specification describes five grants for acquiring an access token:

- Authorization code grant  
- Implicit grant  
- Resource owner credentials grant  
- Client credentials grant  
- Refresh token grant

For more details, please check the link: [https://oauth.net/2/](https://oauth.net/2/)

## Before We Start

Mule supports various security policies such as Client ID enforcement, HTTP Basic authentication, Spring Authentication, LDAP security manager, etc. to name a few. Most importantly, it supports OAuth2.

As per Mule documentation, it supports two providers out-of-the box. They are:

- OpenAM versions 11 or 12  
- PingFederate

These providers can be configured in the Access Management section of Anypoint Platform. Alternatively, one can use the OAuth 2.0 Access Token Enforcement using External Provider policy to secure an API in Anypoint Platform.

In this article, I am going to describe how to create an OAuth2 External Module with grant type Client credentials and apply the module against a simple API.

## Let's Get Our Hands Dirty

Mule documentation provides an [example](https://docs.mulesoft.com/api-manager/about-configure-api-for-oauth) of how to use External OAuth Provider for client authentication; however, the documentation does not fully explain the internal workings of what goes on under the hood. Therefore, in this article, I will try to explain some internal processes as well as mount an External OAuth2 Provider.

The article will be divided into the following parts:

- -Creating a simple API in API Manager
- -Implementation of the API and publishing it to Cloudhub
- -Creating an External OAuth2 Provider
- -Creating Proxy and Portal for the API as well as applying Security Policy
- -Testing OAuth2

## Creating a Simple API in API Manager

I have created a very simple API named **employee** (version v1) in the API Manager. The code snippet is as shown below:

![](https://blog.avenuecode.com/hs-fs/hubfs/Anupam/raml_employees_v1.png?width=540&name=raml_employees_v1.png "raml_employees_v1.png")

## Implementing the API and Publishing it to Cloudhub

Now, implement the API in a project. I am using the simplest implementation for this article because it's not our main concern. Here is the simple implementation of the API:

![Image title](https://dzone.com/storage/temp/5393693-screen-shot-2017-05-24-at-32628-pm.png)

 

As per the implementation, if we hit [http://localhost:8081/api/employees](http://localhost:8081/api/employees) we should receive the result in local. Let's suppose that after deploying it to Cloudhub the service is available at: [http://employees-service.cloudhub.io/api/employees](http://employees-service.cloudhub.io/api/employees)

 Creating the External OAuth2 Provider

This is the most exciting part! Here is the complete source [code](https://github.com/anupamgogoi0907/oauth2/tree/master/oauth-provider). The code is extremely simple, but needs some explanation.

### How Does Your Application Connect to the API Manager?

Try running any Mule project, and you should observe this log output:

![Image title](https://dzone.com/storage/temp/5393774-screen-shot-2017-05-24-at-33537-pm.png)

Internally, there is an agent class **APIPlatformClientCoreExtension** that looks for two property values (**client\_id** and **client\_secret**) to connect to the Anypoint API Manager. So, what are **client\_id** and **client\_secret**? These are simply the credentials of your Anypoint Platfrom. 

Just browse to the organization link of your Anypoint Platform account, and you should see this infomation:

![Image title](https://dzone.com/storage/temp/5393841-screen-shot-2017-05-24-at-34028-pm.png)

You can provide these credentials in the **mule-app.properties** of your project as shown below:

![Image title](https://dzone.com/storage/temp/5393888-screen-shot-2017-05-24-at-34255-pm.png)

 

That's it! Now run the project and you should see the following logs:

 ![Image title](https://dzone.com/storage/temp/5393917-screen-shot-2017-05-24-at-34533-pm.png)

This means that now your application can connect directly to the API Manager. Awesome, right?

### How to Create the External OAuth2 Provider

To create an OAuth2 provider, you must have the **Enterprise Security** module installed in your Anypoint Studio. Please read the first part of this [article](https://dzone.com/articles/mule-message-encryption-jce) about how to install the security module and create a maven project in order to use its security components.

The OAuth2 [provider](https://github.com/anupamgogoi0907/oauth2/tree/master/oauth-provider) that I have created is very simple, as shown below:

![Image title](https://dzone.com/storage/temp/5393983-screen-shot-2017-05-24-at-35914-pm.png)

The most important part is the configuration of the OAuth provider module:

![Image title](https://dzone.com/storage/temp/5393995-screen-shot-2017-05-24-at-40221-pm.png)

From the diagram, it's clear that the Access token url is **oauth/token** and Authorization url is **oauth/authorize,** but is that enough? Of course not! So, what's the complete url for the Access token then? Let's dig into this.

Let's look at the xml configuration:

![](https://blog.avenuecode.com/hs-fs/hubfs/Anupam/Screen%20Shot%202017-05-24%20at%206.02.47%20PM.png?width=680&height=232&name=Screen%20Shot%202017-05-24%20at%206.02.47%20PM.png "Screen Shot 2017-05-24 at 6.02.47 PM.png")

 

In the **oauth2-provider:config** element, we have defined **listenerConfig-ref** so that it refers to the HTTP listener which is localhost and with the port 8081. So, our Access token url will be:

[http://localhost:8081/oauth/token](http://localhost:8081/oauth/token)?<params>

(We will go to the paramssoon!)

You can see that the **clientStore-ref** element of the **oauth2-provider** configuration is pointing to: 

<api-platform-gw:client-store id="my-client-store" doc:name="Client Store" />

 

So what is this? It's where the magic happens. When the application is connected to the API Manager (as explained in the previous section), it gets all the information from the clients (client\_id, client\_secret) and stores them in a store. In this case, I named it **my-client-store**.

That's it. It's the simplest External OAuth2 provider. 

### Test the OAuth2 Provider

Now let's test our OAuth2 provider. Run the project and in Postman, fire the request with the following request params to [http://localhost:8081/oauth/token](http://localhost:8081/oauth/token):

**grant\_type**=client\_credentials

**client\_id**=any client\_id registered in your Anypoint platform. We simply send our Anypoint Platform client\_id.

**client\_secret**=client\_secret, related to the client\_id, registered in your Anypoint platform. We simply send our Anypoint Platform client\_secret.

![Image title](https://dzone.com/storage/temp/5394338-screen-shot-2017-05-24-at-44233-pm.png)

And in return you get the access token. Awesome!

### Validate the Access Token

Now let's look into the code again:

![Image title](https://dzone.com/storage/temp/5394345-screen-shot-2017-05-24-at-44513-pm.png)

If you look into the **Operation** of the OAuth2 provider, you can see that we have defined it as **Validate**. Now, look into the HTTP Listener path:

![Image title](https://dzone.com/storage/temp/5394349-screen-shot-2017-05-24-at-44620-pm.png)

So, to validate the access token retrieved in the previous section we must make a request to:

[http://localhost:8081/app/validate?access\_token=](http://localhost:8081/app/validate?access_token=)<access token received>

Here is the response:

 {"expires\_in":86009,"scope":"", "client\_id":"9b54d2f696644a1896de68b1be8060d9"}

 

This means that our token is valid.

### Deploy the Provider in Cloudhub

Now, let's deploy the provider in Cloudhub:

![Image title](https://dzone.com/storage/temp/5394433-screen-shot-2017-05-24-at-45817-pm.png)

Now, let's fire the same thing to the following url:

![Image title](https://dzone.com/storage/temp/5394596-screen-shot-2017-05-24-at-51515-pm.png)

That's it! Our Provider is working perfectly, so let's validate the token and fire the request to: 

[http://provider.cloudhub.io/app/validate?access\_token=](http://provider.cloudhub.io/app/validate?access_token=)<obtained in the previous step>

You should get a positive response.

## Creating  Proxy and Portal for the API and Applying Security Policy

**Create Proxy**

Once our API definition and implementation are in hand, we can create proxy for the API. Now what is API Proxy ? In short, API Proxy is a layer that sits above our API implementation. It serves as kind of shield to protect our API implementation. Through API Proxy, one can govern the APIs by applying various security policies, SLA tiers, etc. Here's how you can create the API Proxy:

Click your API and its version (employee, v1) so you can see the API Status block. Then, click the **configure endpoint** link and configure the proxy. 

![Image title](https://dzone.com/storage/temp/5394254-screen-shot-2017-05-24-at-42509-pm.png)

Here, the most important thing is the **Implementation URI** that you point towards the actual implementation of the API. In our case, it will be [http://employees-service.cloudhub.io/api](http://employees-service.cloudhub.io/api), which we have implemented and deployed in Cloudhub as described in the previous section.

Then configure the proxy:

![Image title](https://dzone.com/storage/temp/5394277-screen-shot-2017-05-24-at-42835-pm.png)

The proxy url will be made **public** for the users. In our case it is: [http://employee-proxy.cloudhub.io/employees](http://employee-proxy.cloudhub.io/employees).

### Create Portal

After defining the proxy, let's create a portal for our API. Browse the API, click its version, and create a basic portal. Here is a snapshot of my portal:

![Image title](https://dzone.com/storage/temp/5394408-screen-shot-2017-05-24-at-45212-pm.png)

 

### Apply Security Policy

Browse the API and its version, and click it. In the left hand side pane, click the Policies link and apply the External OAuth2 policy, as shown below:

![Image title](https://dzone.com/storage/temp/5394420-screen-shot-2017-05-24-at-45415-pm.png)

 

In the Access token validation ur,l please enter: [http://provider.cloudhub.io/app/validate](http://provider.cloudhub.io/app/validate)

![Image title](https://dzone.com/storage/temp/5394628-screen-shot-2017-05-24-at-52029-pm.png)

 

## Testing OAuth2

Now, let's try to access: [http://employees-proxy.cloudhub.io/employees](http://employees-proxy.cloudhub.io/employees)

You shoud get this response: 

 { "error": "invalid\_request", "description": "The required parameter access token is missing." }

 

Now, let's make a Client app request to the API in its portal.

![Image title](https://dzone.com/storage/temp/5394681-screen-shot-2017-05-24-at-52835-pm.png)

With the client\_id and client\_secret received, you can now get the access token: 

![Image title](https://dzone.com/storage/temp/5394693-screen-shot-2017-05-24-at-52941-pm.png)

Finally, let's access our employees' service:

![Image title](https://dzone.com/storage/temp/5394711-screen-shot-2017-05-24-at-53111-pm.png)

 

You can now successfully access the service using the OAuth token!

## Conclusion

In this tutorial, I have shown how to apply OAuth2 to manage the Clients using an External Provider. If you encounter problems while configuring the OAuth2 provider, set the **http.port=8081** in the **init.properties** file and if you want to know more about our MuleSoft solutions, don't hesitate to contact us and learn why leading enterprise organizations are turning to Avenue Code as the preferred systems integrator for MuleSoft Anypoint Platform.

[![Let's Talk Mule!](https://no-cache.hubspot.com/cta/default/2564010/ec30ce5c-642a-48b5-8f83-4d8282ee332b.png)](https://cta-redirect.hubspot.com/cta/redirect/2564010/ec30ce5c-642a-48b5-8f83-4d8282ee332b)

---

### Author

# Anupam Gogoi

 Anupam Gogoi is an Integration Engineer at Avenue Code. He has been working in software development for about 9 years, implementing solutions in Java technologies as well as in SOA domain. He is a hardcore JAVA and MIDDLEWARE evangelist.

---

### Related Posts

### New Horizons for Solution Architects

[READ MORE](https://blog.avenuecode.com/new-horizons-for-solution-architects?hsLang=en-us)

### How to Use Circuit Breaker Resilience in Your API Integration

[READ MORE](https://blog.avenuecode.com/how-to-use-circuit-breaker-resilience-in-your-api-integration?hsLang=en-us)

### How to Run Rust from Python

[READ MORE](https://blog.avenuecode.com/how-to-run-rust-from-python?hsLang=en-us)

### Deep Dive into MuleSoft Internals - API Tracking

[READ MORE](https://blog.avenuecode.com/what-you-need-to-know-about-api-tracking-in-mulesoft?hsLang=en-us)

### Leave a Comment!

### Avenue Code Social

[![Facebook Icon](https://blog.avenuecode.com/hubfs/Images/Blog/facebook.png?t=1486470796564)](https://www.facebook.com/avenuecode)

[![Twitter Icon](https://blog.avenuecode.com/hubfs/Images/Blog/twitter.png?t=1486470796842)](https://twitter.com/AvenueCode)

[![LinkedIn Icon](https://blog.avenuecode.com/hubfs/Images/Blog/linkedin.png?t=1486470796556)](https://www.linkedin.com/company/avenue-code)

### Newsletter

Want to stay on top of all tips and news from Avenue Code?

### Popular Snippets

![ac-logo-inverted.svg](https://blog.avenuecode.com/hubfs/Images/Logos/ac-logo-inverted.svg "ac-logo-inverted.svg")

### About Us

- [Who We Are](https://www.avenuecode.com/who-we-are)
- [What We Do](https://www.avenuecode.com/what-we-do)
- [Portfolio](https://www.avenuecode.com/portfolio)
- [Partners](https://www.avenuecode.com/partners)
- [News](https://www.avenuecode.com/news)
- [Events](https://www.avenuecode.com/events)
- [Blog](https://blog.avenuecode.com/)
- [Contact](https://www.avenuecode.com/contact)

### Our Offices

San Francisco

[+1 415 766 4178](tel:+553125161448) [ac.inquiries@avenuecode.com](mailto:brazil.info@avenuecode.com)

Belo Horizonte

[+55 31 2516 1448](tel:+553125161448) [brazil.info@avenuecode.com](mailto:brazil.info@avenuecode.com)

São Paulo

[+55 11 3205 3232](tel:+553125161448) [brazil.info@avenuecode.com](mailto:brazil.info@avenuecode.com)

### We're Hiring!

- [Belo Horizonte](https://www.avenuecode.com/who-we-are)
- [New York](https://www.avenuecode.com/what-we-do)
- [San Francisco](https://www.avenuecode.com/portfolio)
- [São Paulo](https://www.avenuecode.com/partners)

---

©2015 - 2017 Avenue Code

[![Facebook Icon](https://blog.avenuecode.com/hubfs/Images/Icons/facebook-2.png)](https://www.facebook.com/avenuecode) [![Twitter Icon](https://blog.avenuecode.com/hubfs/Images/Icons/twitter-2.png)](https://twitter.com/AvenueCode) [![LinkedIn Icon](https://blog.avenuecode.com/hubfs/Images/Icons/linkedin-2.png)](https://www.linkedin.com/company/avenue-code) [![Glassdoor Icon](https://blog.avenuecode.com/hubfs/Images/Icons/glassdoor-icon-1.png)](https://www.glassdoor.com/Overview/Working-at-Avenue-Code-EI_IE456173.11,22.htm) [![YouTube Icon](https://blog.avenuecode.com/hubfs/Images/Icons/youtube-2.png)](https://www.youtube.com/user/AvenueCodePlay)

Please enable JavaScript to view the [comments powered by Disqus.](http://disqus.com/?ref_noscript)

© 2026 Avenue Code

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Anupam Gogoi",
    "url" : "https://blog.avenuecode.com/author/anupam-gogoi"
  },
  "dateModified" : "2019-07-17T15:19:26.916Z",
  "datePublished" : "2017-10-03T19:00:00.000Z",
  "headline" : "How to Beef Up Your Security Using OAuth2 External Provider In Mule",
  "image" : [ "https://blog.avenuecode.com/hubfs/matt-artz-353284.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.avenuecode.com/using-oauth2-external-provider-in-mule",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.avenuecode.com/hubfs/Avenue%20Code%20New%20Logos%20-%202023/Avenue%20Code-primary%20versions_LOGO%20HORIZONTAL%20group%201-7.png"
    },
    "name" : "Avenue Code"
  }
}
```