Skip Navigation
Expand
Enforcing profile permissions on SOAP and REST API calls
Answer ID 7156   |   Last Review Date 10/09/2019

How can I make sure the profile permissions are enforced for an account's SOAP and REST API calls?

Environment:

Oracle Service Cloud
May 2013 and newer

Resolution:

There is a hidden configuration setting which maps profile permissions to SOAP and REST API permissions:

SERVER_ACCESS_CONTROL_ENABLED
-  This setting specifies whether server-side access control enforcement is enabled.
-  This setting is enabled by default for all new sites, but is disabled on some older sites.

As this setting is hidden, if you would like it to be enabled submit a service request to Ask Technical Support, but please take these facts into consideration before doing so:

1. It will affect all your current integrations
2. Once enabled, it cannot be disabled

It is highly recommended that you test its implications on a test site before enabling it on your production site.

Available Languages for this Answer:

Notify Me
The page will refresh upon submission. Any pending input will be lost.