Authentication in Pega Connect-REST?

When Pega calls another system over REST, the other side wants to know who is calling. A Connect-REST rule handles that on its Authentication settings, and the credentials themselves live in a separate rule so they are never typed into the connector.

Where authentication is set

On the Connect-REST rule, the Authentication section has an option to authenticate the call and a field that points to an Authentication Profile. If the box is not ticked, Pega sends the request with no credentials, which only works for open APIs.

Common schemes

SchemeHow it worksTypical use
BasicUsername and password sent with the requestInternal services and quick integrations
NTLMWindows domain credentialsServices behind a Windows or IIS server
OAuth 2.0Pega first gets an access token, then sends it as a bearer tokenCloud APIs and most modern partners
API key or custom headerA fixed key added to a header by the connector or a data transformSimple SaaS APIs

The exact list of profile types depends on your Pega version, so check the Authentication Profile form on your own system.

A worked example

A bank calls a credit-score service that uses OAuth 2.0 client credentials.

  1. Create an Authentication Profile of type OAuth 2.0 with the token endpoint, client ID, client secret and scope.
  2. Open the Connect-REST rule for the score service and tick Authenticate.
  3. Select the profile you just created.
  4. Run the connector. Pega calls the token endpoint, caches the access token, adds an Authorization: Bearer ... header to every request, and asks for a new token when the old one expires.

Good practice

  • Keep secrets in the profile, never in a data transform or a property. The profile stores them encrypted.
  • Use a different profile for each environment, so a test client ID never reaches production.
  • Prefer OAuth 2.0 over Basic where the provider supports it, because tokens expire and can be limited by scope.
  • Always call over HTTPS.

Common problems

  • 401 Unauthorized: wrong credentials, or the token has expired or has the wrong scope.
  • 403 Forbidden: authentication worked but the account is not allowed to use that endpoint.
  • The connector works in test but fails in production: the profile was not migrated with the ruleset, or points at a test token URL.

Interview tip

Say that authentication for outbound REST is configured through an Authentication Profile, name two schemes, and explain where the secret is kept. Continue with what an Authentication Profile is and the wider Security topic.

1 comment: