An Authentication Profile is a Pega rule that stores how your application proves its identity to another system. It is the outbound side of authentication: your Pega application is the caller, and the profile holds the settings and secrets needed to make that call succeed. It is used by connector rules such as Connect-REST and Connect-SOAP.
Why a separate rule?
Putting a username and password directly in a connector would scatter secrets across many rules and make every change a code change. A profile keeps them in one place, encrypted, and lets many connectors share it. Change the secret once and every connector that uses the profile picks it up.
What a profile contains
- Type: for example Basic, NTLM or OAuth 2.0. The available types depend on your Pega version.
- Credentials: user name and password, or client ID and client secret.
- Token settings for OAuth 2.0: the token endpoint URL, scope, and the grant type (such as client credentials).
- Security options: a keystore or certificate reference when the provider requires signed requests.
Example: a payments API
Your bank calls a payment gateway that issues OAuth 2.0 tokens.
- Create the profile
PaymentsGatewayOAuthof type OAuth 2.0. - Enter the gateway's token URL, your client ID and client secret, and the scope
payments.write. - Save it in the integration ruleset.
- On each Connect-REST rule for the gateway, tick Authenticate and choose
PaymentsGatewayOAuth.
At run time Pega requests a token, keeps it until it expires, and adds it to the header of every request. The connector rules never see the secret.
Authentication Profile vs Authentication Service
| Authentication Profile | Authentication Service | |
|---|---|---|
| Direction | Outbound, Pega calls someone | Inbound, someone signs in to Pega |
| Used by | Connect-REST, Connect-SOAP | Login, SSO, service rules |
| Example | Get a token from a payment API | Sign users in with SAML or OpenID Connect |
Tips
- Use one profile per target system and environment.
- Test the profile from the connector's Run tab before wiring it into a flow.
- Make sure the profile is in a ruleset that migrates with the application, or the connector will fail after deployment.
Related reading: Authentication in Pega Connect-REST and the Security label.
No comments:
Post a Comment