<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic OAuth impersonation client changes from trusted to required after publish in App Development</title>
    <link>https://community.qlik.com/t5/App-Development/OAuth-impersonation-client-changes-from-trusted-to-required/m-p/2549211#M110270</link>
    <description>&lt;P&gt;We are embedding a private Qlik Cloud sheet inside a React app and want backend-issued OAuth impersonation tokens so users are not redirected to Qlik login.&lt;/P&gt;
&lt;P&gt;Tenant:&lt;BR /&gt;&lt;A href="https://3sndgsisxteabed.in.qlikcloud.com" target="_blank" rel="noopener"&gt;https://3sndgsisxteabed.in.qlikcloud.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;We created an OAuth Web client with M2M user impersonation.&lt;BR /&gt;Before publish, consent method shows trusted.&lt;BR /&gt;After publish, it changes to required.&lt;/P&gt;
&lt;P&gt;Then backend POST /oauth/token with grant_type=urn:qlik:oauth:user-impersonation fails with:&lt;BR /&gt;oauth client is not approved with trusted consent method&lt;/P&gt;
&lt;P&gt;Is trusted consent supported for published impersonation clients on Qlik Cloud?&lt;BR /&gt;Why does publish change it back to required?&lt;BR /&gt;Is there any supported no-redirect embed approach for this tenant if impersonation is blocked?&lt;/P&gt;</description>
    <pubDate>Fri, 15 May 2026 13:04:28 GMT</pubDate>
    <dc:creator>Ra_3465_2026</dc:creator>
    <dc:date>2026-05-15T13:04:28Z</dc:date>
    <item>
      <title>OAuth impersonation client changes from trusted to required after publish</title>
      <link>https://community.qlik.com/t5/App-Development/OAuth-impersonation-client-changes-from-trusted-to-required/m-p/2549211#M110270</link>
      <description>&lt;P&gt;We are embedding a private Qlik Cloud sheet inside a React app and want backend-issued OAuth impersonation tokens so users are not redirected to Qlik login.&lt;/P&gt;
&lt;P&gt;Tenant:&lt;BR /&gt;&lt;A href="https://3sndgsisxteabed.in.qlikcloud.com" target="_blank" rel="noopener"&gt;https://3sndgsisxteabed.in.qlikcloud.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;We created an OAuth Web client with M2M user impersonation.&lt;BR /&gt;Before publish, consent method shows trusted.&lt;BR /&gt;After publish, it changes to required.&lt;/P&gt;
&lt;P&gt;Then backend POST /oauth/token with grant_type=urn:qlik:oauth:user-impersonation fails with:&lt;BR /&gt;oauth client is not approved with trusted consent method&lt;/P&gt;
&lt;P&gt;Is trusted consent supported for published impersonation clients on Qlik Cloud?&lt;BR /&gt;Why does publish change it back to required?&lt;BR /&gt;Is there any supported no-redirect embed approach for this tenant if impersonation is blocked?&lt;/P&gt;</description>
      <pubDate>Fri, 15 May 2026 13:04:28 GMT</pubDate>
      <guid>https://community.qlik.com/t5/App-Development/OAuth-impersonation-client-changes-from-trusted-to-required/m-p/2549211#M110270</guid>
      <dc:creator>Ra_3465_2026</dc:creator>
      <dc:date>2026-05-15T13:04:28Z</dc:date>
    </item>
  </channel>
</rss>

