PingIDM

Remote proxy authentication methods

The remote proxy supports two authentication methods:

Bearer authentication (OAuth 2.0)

Use for connections to a remote instance that authenticates through PingAM, or to an Advanced Identity Cloud tenant.

{
  "enabled": true,
  "authType": "bearer",
  "instanceUrl": "https://<remote-instance-fqdn>/openidm/",
  "clientId": "<clientIDName>",
  "clientSecret": "<client-secret>", (1)
  "scope": ["fr:idm:*"],
  "tokenEndpoint": "https://<remote-instance-fqdn>/am/oauth2/realms/root/realms/alpha/access_token",
  "tokenEndpointAuthMethod": "client_secret_post",
  "scopeDelimiter": " "
}
1 Store the client secret in a secret store instead of using a plaintext value.

Required properties: authType, clientId, clientSecret, instanceUrl, tokenEndpoint, tokenEndpointAuthMethod, and scope.

Basic authentication

Use for connecting to a self-managed PingIDM instance that doesn’t authenticate through PingAM.

{
  "enabled": true,
  "authType": "basic",
  "instanceUrl": "https://<remote-instance-fqdn>/openidm/",
  "userName": "openidm-admin",
  "password":  "<password>" (1)
}
1 Store the password in a secret store instead of using a plaintext value.

Required properties: authType, userName, instanceUrl, and password.

Configuration properties reference

External IDM proxy configuration properties
Property Required Description

enabled

No

Enable or disable the proxy. Default is true.

authType

Yes

Authentication method: basic or bearer.

instanceUrl

Yes

Remote instance URL. Must end with a trailing slash (/).

scope

Yes (bearer only)

OAuth 2.0 scopes, for example ["fr:idm:*"].

scopeDelimiter

No

Scope delimiter. Default is a space.

userName

Yes (basic only)

Username for basic auth.

password

Yes (basic only)

Password for basic auth.

clientId

Yes (bearer only)

OAuth 2.0 client ID.

clientSecret

Yes (bearer only)

OAuth 2.0 client secret. Store it in a secret store rather than using a plaintext value.

tokenEndpoint

Yes (bearer only)

OAuth 2.0 token endpoint URL.

tokenEndpointAuthMethod

Yes (bearer only)

Must be client_secret_post.

For any request forwarded to the remote instance that includes an X-Requested-With header, the remote proxy sets the header value to RemoteIDMProxy.