Secure Connection to Live Platform REST API Server

Connection to the UMP-365 server from a REST API client interface requires an authentication token. The token is generated based on the provided credentials. These credentials are derived from the 'LiveCloud-APIToken' registration that must be created on the Service Provider tenant, together with the inherited scope (client id) from the AudioCodes SysAdmin tenant registration:

■ grant_type: client_credentials
■ client_id: 'LiveCloud-APIToken' Service Provider Application (client) ID
■ client_secret: 'LiveCloud-APIToken' Service Provider Application client secret
■ scope: AudioCodes Application Registration 'LiveCloud-APIToken'

The Authentication flow is described below:

1. Request a token: The API client sends a request to your tenant's token endpoint with grant_type=client_credentials , its client_id and client_secret ,and scope=api://9d576dc4-b85d-4571-880e-4c6ed4c08c31/.default .
2. Receive the token: Azure AD returns a signed access token (JWT) that is valid for about one hour ( expires_in: 3599 ).
3. Call the API: The client calls a UMP Public API endpoint, for example /api/v2/customer , with the header Authorization: Bearer <token> .
4. Validate the token: UMP-365 checks the token's signature, its audience (the server app ID) and its issuer (which must be listed in ValidIssuers ). If all three pass, it accepts the request.
5. Process: UMP runs the request and builds the result.
6. Response: The response returnes to the client. When the token expires, the client repeats steps 1–2.

The Service Provider 'LiveCloud-APIToken' can be generated manually or automatically using an AudioCodes provided script:

■ Manually Deploying REST API Application
■ Automatically Deploying REST API Application with PowerShell Script