Access denied when creating server-to-server connection to AEM Assets API
In Adobe Experience Manager as a Cloud Service (AEMaaCS), access denied errors occur when creating a server-to-server connection to the AEM Assets Author API or while creating a technical account in Adobe Developer Console. To resolve the issue, assign the correct roles and product profiles in Admin Console.
Description description
Environment
Adobe Experience Manager as a Cloud Service (AEMaaCS) (all versions)
Issue/Symptoms
- You have developer and administrative access but are unable to add the AEM Assets Author API using a server-to-server connection to an existing service account project in the Adobe Developer Console.
- You are unable to create a technical account for AEM integration in the Cloud Manager Developer Console.
- Attempts result in access denied errors, even when the necessary permissions appear to be configured in AEM and Cloud Manager.
- The option to create a server-to-server connection is not visible in the Adobe Developer Console.
- The AEM Assets Author API card in the Developer Console displays License required.
- No specific error codes are displayed, but the inability to proceed remains consistent across both operations.
Root cause
Missing IMS roles or incorrect product profile assignments in Admin Console cause access denied errors, rather than permissions configured within AEM or Cloud Manager.
Resolution resolution
Follow the steps below to address the issue:
-
Verify product entitlements and product profiles:
- In Admin Console, navigate to Products and confirm that Adobe Experience Manager as a Cloud Service – Assets is present with an Author context for the relevant environment.
- In the Adobe Developer Console, check whether the AEM Assets Author API card displays License required, which indicates an entitlement or product profile issue.
-
Enable the AEM Assets API Users service:
- In Admin Console, go to Products
>AEM as a Cloud Service – Assets and select the Author product instance. - Open the product profile used for API access (for example, AEM Assets – Author – Dev – API Users).
- In the Services tab, ensure that AEM Assets API Users is enabled.
- In Admin Console, go to Products
-
Assign the correct role for server-to-server access:
- In Admin Console, navigate to Products
>AEM as a Cloud Service – Assets>[Author instance]>[API product profile]. - Open the Users tab and add the required account.
- Assign the Developer or Developer Admin role, as assigning only the User role is insufficient.
- Save the changes, wait a few minutes, then sign out and sign back in to the Developer Console.
- In Admin Console, navigate to Products
-
Ensure IMS system administrator role for technical account creation:
- To create technical accounts in the Cloud Manager Developer Console, ensure the account has the IMS System Administrator role assigned.
- Confirm this in Admin Console under Users
>[account]>Admin Roles.