When Pega calls another system over REST, the other side wants to know who is calling. A Connect-REST rule handles that on its Authentication settings, and the credentials themselves live in a separate rule so they are never typed into the connector.
Where authentication is set
On the Connect-REST rule, the Authentication section has an option to authenticate the call and a field that points to an Authentication Profile. If the box is not ticked, Pega sends the request with no credentials, which only works for open APIs.
Common schemes
| Scheme | How it works | Typical use |
|---|---|---|
| Basic | Username and password sent with the request | Internal services and quick integrations |
| NTLM | Windows domain credentials | Services behind a Windows or IIS server |
| OAuth 2.0 | Pega first gets an access token, then sends it as a bearer token | Cloud APIs and most modern partners |
| API key or custom header | A fixed key added to a header by the connector or a data transform | Simple SaaS APIs |
The exact list of profile types depends on your Pega version, so check the Authentication Profile form on your own system.
A worked example
A bank calls a credit-score service that uses OAuth 2.0 client credentials.
- Create an Authentication Profile of type OAuth 2.0 with the token endpoint, client ID, client secret and scope.
- Open the Connect-REST rule for the score service and tick Authenticate.
- Select the profile you just created.
- Run the connector. Pega calls the token endpoint, caches the access token, adds an
Authorization: Bearer ...header to every request, and asks for a new token when the old one expires.
Good practice
- Keep secrets in the profile, never in a data transform or a property. The profile stores them encrypted.
- Use a different profile for each environment, so a test client ID never reaches production.
- Prefer OAuth 2.0 over Basic where the provider supports it, because tokens expire and can be limited by scope.
- Always call over HTTPS.
Common problems
- 401 Unauthorized: wrong credentials, or the token has expired or has the wrong scope.
- 403 Forbidden: authentication worked but the account is not allowed to use that endpoint.
- The connector works in test but fails in production: the profile was not migrated with the ruleset, or points at a test token URL.
Interview tip
Say that authentication for outbound REST is configured through an Authentication Profile, name two schemes, and explain where the secret is kept. Continue with what an Authentication Profile is and the wider Security topic.
Commonly asked in interview
ReplyDelete