Cloud API implementation checklist for external users
To configure the system APIs for authentication for external users, you may need to do the following tasks:
| Task | More Information |
|---|---|
| Enable asymmetric encryption | Enabling Cloud API bearer token authentication |
| Provide deployment information | Enabling Cloud API bearer token authentication |
| Configure the IdP to store user information | Enabling Cloud API bearer token authentication |
| Register the caller application with Guidewire Hub | Enabling Cloud API bearer token authentication |
| Create or modify API roles | Cloud API endpoint access |
Review the resource access provided by the
cc_contactAuthorizationIds and cc_gwabuid
resource access strategies (ClaimCenter) |
Cloud API resource access |
Review the resource access provided by the pc_accountNumbers
resource strategy for account holders or the pc_producerCodes
resource strategy for producers (PolicyCenter) |
Cloud API resource access |
Review the resource access provided by the
bc_contactAuthorizationIds resource access strategy for account
holders or the bc_producerCodes resource strategy for producers
(BillingCenter) |
Cloud API resource access |
| Configure the proxy user | Cloud API proxy user access |
Configure the IExpandTokenPlugin plugin to retrieve additional
authorization values, if needed |
Configuring the Cloud API IExpandTokenPlugin |
Configure the RestV1JobTypesConfigurationPlugin plugin to
provide account holders access to additional job types, if needed
(PolicyCenter) |
Configuring Cloud API job type access for account holders |
To make a Cloud API call for external users, the caller application must:
- Request a code from Guidewire Hub
- Use the code to request a JWT from Guidewire Hub
- Include the JWT with the system API call
For more information, see Sending authenticated Cloud API calls for external users.