OAuth 2.0 Authentication

This section provides the details of the required permissions for the OAuth 2.0 Authentication Type:

  1. Create the API Client.

    For more information on API Client creation, refer to Create the API Client for Integration.

  2. The Workday Account used for the API Client to generate a refresh token must be an integration user and must have all the permissions as described in Basic Authentication.

  3. Add one of the following functional areas under the API Client Integration used for OAuth 2.0:

    • Staffing

    • System

    • Contact Information

    • Personal Data

    • Integration

    • Organization and Roles

  4. Provide access to the Integration Security Group for the Workday Query Language Domain in the System Functional Area. For more information, refer to Set Permissions to Workday Query Language Domain.

  5. Provide access to Integration Security Group to the Worker data source. For more information, refer to Set Permissions to the Worker Data Source.