The next step is to configure a client application as consumer of the resource server and assign users and groups to it so only users that are associated to the client application are allowed to obtain a valid OAuth 2.0 token.
Follow these steps to accomplish the configuration:
- From the main menu (top left-hand side), select Applications and once the Applications home page opens click on Add:
- Select Trusted Application as this example describes how to implemented a resource owner password grant flow which assumes that a consumer application is trusted: