Cloud API authentication flow for unauthenticated callers

The following diagram identifies the flow of authentication and authorization information for unauthenticated callers. Colors are used in the following ways:

  • Orange - credentials information
  • Blue - endpoint access information
  • Green - resource access information
  • Red - proxy user and session user information

Some values are used to determine multiple types of access. These values initially appear as black (when they do not apply to a single type of access), and then later appear in one or more specific colors (to reflect the value is being used at that point in the process for a specific type of access).

In the following example, an API call is triggered by an unauthenticated caller.


Authentication flow for unauthenticated callers
  1. The caller application sends the API request to the InsuranceSuite application. The call includes no JWT, and no authentication information in the header.
  2. The IExpandTokenPlugin plugin is not relevant for unauthenticated callers.
  3. Because the call has no authentication header, the InsuranceSuite application grants endpoint access as defined in the Unauthenticated.role.yaml API role file. (This provides access to metadata endpoints only.)
    Note: When PolicyCenter grants endpoint access as defined in the Unauthenticated.role.yaml API role file, this provides access to metadata endpoints as well as endpoints that can be used to create a new account. This is part of the anonymous auth flow. This only applies to PolicyCenter.
  4. Because the call has no authentication header, InsuranceSuite application grants resource access as defined in the unauthenticatedUser.access.yaml API role file. (This provides no access to business resources.)
  5. To determine which proxy user to assign to the session, the InsuranceSuite application calls the RestAuthenticationSourceCreator plugin. The call has no authentication header. So, the plugin returns the proxy user for unauthenticated users: uauser.
  6. The InsuranceSuite application processes the request.
    1. The session user is the proxy unauthenticated user: uauser.
    2. The endpoint access is defined by Unauthenticated.role.yaml.
    3. The resource access is defined by unauthenticatedUser access.yaml.
  7. The InsuranceSuite application provides the response to the initial call.