External Two squares, one overlapping the bottom one. Top square has an arrow pointing away, as if leading you away

Authorization methods

Purpose

An overview of the authorization methods available when registering an app in the Zywave Admin tool, and the OAuth 2.0 grant types behind them.

User-based OAuth 2.0

Also called 3-legged OAuth, this method uses the Authorization Code grant type. A user logs in to Zywave and consents before your app can access their data, and your app only ever sees data that user has access to.

This is the recommended method for most integrations, and is required any time your app needs to act on behalf of a specific Zywave user.

System-based OAuth 2.0

Also called 2-legged OAuth, this method uses the Client Credentials grant type. Your app authenticates directly to Zywave with its client ID and secret, with no user involved in authorization at all.

Use this only when there's complete trust between your app and the data it's accessing. Your app won't be scoped to any particular user's permissions.

Note: Because there's no user session involved, offline_access and refresh tokens don't apply to apps using System-based OAuth 2.0. A new access token is issued directly from your client credentials whenever you need one.