Cloud API implementation checklist for external users

To configure the system APIs for authentication for external users, you may need to do the following tasks:

Task More Information
Enable asymmetric encryption Enabling Cloud API bearer token authentication
Provide deployment information Enabling Cloud API bearer token authentication
Configure the IdP to store user information Enabling Cloud API bearer token authentication
Register the caller application with Guidewire Hub Enabling Cloud API bearer token authentication
Create or modify API roles Cloud API endpoint access
Review the resource access provided by the cc_contactAuthorizationIds and cc_gwabuid resource access strategies (ClaimCenter) Cloud API resource access
Review the resource access provided by the pc_accountNumbers resource strategy for account holders or the pc_producerCodes resource strategy for producers (PolicyCenter) Cloud API resource access
Review the resource access provided by the bc_contactAuthorizationIds resource access strategy for account holders or the bc_producerCodes resource strategy for producers (BillingCenter) Cloud API resource access
Configure the proxy user Cloud API proxy user access
Configure the IExpandTokenPlugin plugin to retrieve additional authorization values, if needed Configuring the Cloud API IExpandTokenPlugin
Configure the RestV1JobTypesConfigurationPlugin plugin to provide account holders access to additional job types, if needed (PolicyCenter) Configuring Cloud API job type access for account holders

To make a Cloud API call for external users, the caller application must:

  1. Request a code from Guidewire Hub
  2. Use the code to request a JWT from Guidewire Hub
  3. Include the JWT with the system API call

For more information, see Sending authenticated Cloud API calls for external users.