Welcome to the Panopto Community

Please note: All new registrants to the Panopto Community Forum must be approved by a forum moderator or admin. As such, if you navigate to a feature that is members-only, you may receive an error page if your registration has not yet been approved. We apologize for any inconvenience and are approving new members as quickly as possible.

Restricting an API/OAuth Client

We're interested in potentially integrating some tools with Panopto to provide some additional functionality for our courses. With how the API Clients work in Panopto, it doesn't look like there is currently a way to restrict what an application is able to do. So, in a hypothetical situation, if I were to use one of these tools as an admin in our tenant, that application could do anything on the site that I'm able to do (as long as there is an API endpoint). We usually practice good hygiene with these privileged accounts so that doesn't happen, but I'd feel better if it was something we had better control of.

In short, we'd like to scope things down so that integrated platforms are only able to perform specific actions using user tokens generated with a specific API client. Is this something that others have figured out a solution for?

Answers

  • I agree 100%. This is like giving a contractor not just the keys to your house but also your passwords, banking info, the combination to your safe, etc.

    API keys should be able to be scoped with respect to specific folders, actions, etc.

    In Zoom I can create an API key with the ability to perform read or write actions and select from hundreds of types of actions.

    I don't expect that level of granularity to start, but something other than carte blanch is table stakes.

  • Agree with the above comments, and want to note that scoping by folders (especially departmental but more granular subsets would be helpful too) is key for us. This supports individual departments who want to use the APIs but should only have the ability to work with the subsets of content they have access to. We have a lot of talented folks distributed across the enterprise who want to expand their use of Panopto via the APIs, but limiting full site admin credentials to just a few people is a foundational security protocol for us.

Sign In or Register to comment.