Hi @Stephen Li ,
Thanks for reaching out.
To obtain the access token in the ROPC flow, it's essential to include grant_type, scope, and client_id as mandatory parameters.
In the custom policy XML, ensure all necessary parameters are included to acquire the access token. During the ROPC flow, along with the username and password, these parameters are sent to the authorization server for access token retrieval.
Therefore, it's imperative not to regard these parameters as optional when making the request.
Hope this will help.
Thanks,
Shweta
Please remember to "Accept Answer" if answer helped you.