PingOne Advanced Identity Cloud

Remote consent service

Advanced Identity Cloud supports OAuth 2.0 remote consent, allowing you to delegate the user consent-gathering process to an external service.

Advanced Identity Cloud includes a built-in example remote consent service designed for testing and evaluation. This allows you to quickly demonstrate how Advanced Identity Cloud integrates with external consent applications without setting up custom infrastructure first.

The example consent service is for demonstration and testing purposes only and isn’t suitable for production use because you can’t configure the encryption and signing algorithms.

Find information about configuring remote consent in production environments in Remote consent.

  1. In the Advanced Identity Cloud admin console, go to vpn_key Authorization > Remote Consent Service.

  2. If the service isn’t already enabled, click Enable Remote Consent Service.

  3. Configure the following settings:

    Client Name

    The name used to identify this OAuth 2.0 consent service when referenced from other services.

    Authorization Server jwk_uri

    The jwk_uri for retrieving the authorization server signing and encryption keys.

    JWK Store Cache Timeout (in minutes)

    The cache timeout for the JWK store of the authorization server, in minutes.

    JWK Store Cache Miss Cache Time (in minutes)

    The length of time a cache miss is cached, in minutes.

    Consent Response Time Limit (in minutes)

    The time limit set on the consent response JWT before it expires, in minutes.

  4. Click Save.

The following example uses the same Advanced Identity Cloud tenant as both the authorization server and the consent service.

  1. In the Advanced Identity Cloud admin console, go to vpn_key Authorization > Remote Consent Service and configure the consent service as follows:

    1. In Client Name, enter the agent ID of the remote consent agent profile.

      For example, myConsentAgent.

    2. In Authorization Server jwk_uri, enter the URI where the consent service retrieves the keys the authorization server uses to sign and encrypt the consent request. These keys include:

      • The public signing key the consent service uses to verify the signature of the consent request.

      • The public encryption key for the consent response, so that the response can be encrypted (if encryption is enabled).

      The default JWKs URI for remote consent clients is /oauth2/consent_agents/jwk_uri.

      For example, https://<tenant-env-fqdn>/am/oauth2/realms/root/realms/alpha/consent_agents/jwk_uri.

    3. Click Save.

  2. Map the following secret labels to ESV secrets:

    • am.services.oauth2.remote.consent.response.signing.RSA: create an ESV secret named esv-remote-consent-response-signing-rsa containing an RSA key pair (an RS256 signing key).

    • am.services.oauth2.remote.consent.request.encryption: create an ESV secret named esv-remote-consent-request-encryption containing a second RSA key pair (an RSA-OAEP-256 encryption key).

    Each secret must be a PEM-encoded secret containing an RSA key pair. When a certificate is included, the public key is taken from the certificate and must correspond to the private key.

    These keys must match the configuration of the consent service agent profile you create in the next step.

  3. Create a remote consent agent profile by performing the steps in Remote consent agent profile.

    Make sure the following fields are configured correctly for the example consent service:

    • Json Web Key URI: The example consent service provides a realm-specific /oauth2/realms/root/realms/<realm>/consent/jwk_uri path to supply its public keys to the authorization server. For example, https://<tenant-env-fqdn>/am/oauth2/realms/root/realms/alpha/consent/jwk_uri.

      You can verify the ESV secrets configuration before performing an OAuth 2.0 flow by sending a GET request to the jwk_uri endpoint. You should get a successful response with a keys array of two RSA keys. If you get a 500 response ("An error occurred while producing JWK"), ensure the ESVs are valid and correctly mapped.
    • Redirect URL: The example consent service provides a realm-specific consent page. For example, https://<tenant-env-fqdn>/am/oauth2/realms/root/realms/alpha/consent.

  4. Enable remote consent on the OAuth 2.0 provider by performing the steps in Use the profile.

  5. Perform an OAuth 2.0 flow that requires consent. Advanced Identity Cloud renders the consent page using the example consent service.

Deleting the service removes all the consent service configuration.

To delete the service:

  1. In the Advanced Identity Cloud admin console, go to vpn_key Authorization > Remote Consent Service.

  2. At the bottom of the page, click Delete Remote Consent Service.