Secure Connection to Live Platform REST API Server
Connection to the UMP-365 server from a REST API client interface requires an authentication token. The token is generated based on the provided credentials. These credentials are derived from the 'LiveCloud-APIToken' registration that must be created on the Service Provider tenant, together with the inherited scope (client id) from the AudioCodes SysAdmin tenant registration:
|
■
|
grant_type: client_credentials |
|
■
|
client_id: 'LiveCloud-APIToken' Service Provider Application (client) ID |
|
■
|
client_secret: 'LiveCloud-APIToken' Service Provider Application client secret |
|
■
|
scope: AudioCodes Application Registration 'LiveCloud-APIToken' |
The Authentication flow is described below:
|
1.
|
Request a token: The API client sends a request to your tenant's token endpoint with grant_type=client_credentials , its client_id and client_secret ,and scope=api://9d576dc4-b85d-4571-880e-4c6ed4c08c31/.default . |
|
2.
|
Receive the token: Azure AD returns a signed access token (JWT) that is valid for about one hour
( expires_in: 3599 ). |
|
3.
|
Call the API: The client calls a UMP Public API endpoint, for example /api/v2/customer ,
with the header Authorization: Bearer <token> . |
|
4.
|
Validate the token: UMP-365 checks the token's signature, its audience (the server app ID) and its issuer
(which must be listed in ValidIssuers ). If all three pass, it accepts the
request. |
|
5.
|
Process: UMP runs the request and builds the result. |
|
6.
|
Response: The response returnes to the client. When the token expires, the client repeats
steps 1–2. |
The Service Provider 'LiveCloud-APIToken' can be generated manually or automatically using an AudioCodes provided script: