By: Miguel Foo user 12 Aug 2017 at 12:36 a.m. CDT

2 Responses
Miguel Foo gravatar
Heya Trying to implement UMA after reading all the documentation you guys suggested on the [site](https://docs.kantarainitiative.org/uma/wg/oauth-uma-federated-authz-2.0-05.html). What doesn't seem to be explained anywhere is how to allow the RS to update the Resource set. I see the endpoints listed in the [UMA API docs](https://gluu.org/docs/ce/api-guide/uma-api/) I'm wondering if I need to have a valid openidconnect client with scope of uma_protection? Some direction would be appreciated

By Miguel Foo user 12 Aug 2017 at 4:42 a.m. CDT

Miguel Foo gravatar
Never mind I found my answer in this thread https://support.gluu.org/access-management/4393/oauth2-client-credentials-grant-how-do-i-validate-the-token/ Will close the ticket

By Michael Schwartz Account Admin 12 Aug 2017 at 4:10 p.m. CDT

Michael Schwartz gravatar
Also keep in mind that UMA 2.0 is about to come out, if all goes well, by the end of the month. The changes to the RS interaction with the AS are not that great. The biggest change is to the client-AS interaction (no more AAT, improved claims gathering endpoint).