---
title: Remote proxy authentication methods
description: Configure bearer OAuth 2.0 or basic authentication for PingIDM remote proxy connections, with a full configuration properties reference
component: pingidm
version: 8.1
page_id: pingidm:objects-guide:remote-proxy-authentication-methods
canonical_url: https://docs.pingidentity.com/pingidm/8.1/objects-guide/remote-proxy-authentication-methods.html
llms_txt: https://docs.pingidentity.com/pingidm/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
keywords: ["Data Object Model", "Synchronization"]
section_ids:
  remote-proxy-bearer-auth: Bearer authentication (OAuth 2.0)
  remote-proxy-basic-auth: Basic authentication
  remote-proxy-config-ref: Configuration properties reference
---

# Remote proxy authentication methods

The remote proxy supports two authentication methods:

* [Bearer authentication (OAuth 2.0)](#remote-proxy-bearer-auth)

* [Basic authentication](#remote-proxy-basic-auth)

## Bearer authentication (OAuth 2.0)

Use for connections to a remote instance that authenticates through PingAM, or to an Advanced Identity Cloud tenant.

```json
{
  "enabled": true,
  "authType": "bearer",
  "instanceUrl": "https://<remote-instance-fqdn>/openidm/",
  "clientId": "<clientIDName>",
  "clientSecret": "<client-secret>", (1)
  "scope": ["fr:idm:*"],
  "tokenEndpoint": "https://<remote-instance-fqdn>/am/oauth2/realms/root/realms/alpha/access_token",
  "tokenEndpointAuthMethod": "client_secret_post",
  "scopeDelimiter": " "
}
```

|       |                                                                                                                       |
| ----- | --------------------------------------------------------------------------------------------------------------------- |
| **1** | Store the client secret in a [secret store](../security-guide/secret-stores.html) instead of using a plaintext value. |

Required properties: `authType`, `clientId`, `clientSecret`, `instanceUrl`, `tokenEndpoint`, `tokenEndpointAuthMethod`, and `scope`.

## Basic authentication

Use for connecting to a self-managed PingIDM instance that doesn't authenticate through PingAM.

```json
{
  "enabled": true,
  "authType": "basic",
  "instanceUrl": "https://<remote-instance-fqdn>/openidm/",
  "userName": "openidm-admin",
  "password":  "<password>" (1)
}
```

|       |                                                                                                                  |
| ----- | ---------------------------------------------------------------------------------------------------------------- |
| **1** | Store the password in a [secret store](../security-guide/secret-stores.html) instead of using a plaintext value. |

Required properties: `authType`, `userName`, `instanceUrl`, and `password`.

## Configuration properties reference

**External IDM proxy configuration properties**

| Property                  | Required          | Description                                                                                                                      |
| ------------------------- | ----------------- | -------------------------------------------------------------------------------------------------------------------------------- |
| `enabled`                 | No                | Enable or disable the proxy. Default is `true`.                                                                                  |
| `authType`                | Yes               | Authentication method: `basic` or `bearer`.                                                                                      |
| `instanceUrl`             | Yes               | Remote instance URL. Must end with a trailing slash (`/`).                                                                       |
| `scope`                   | Yes (bearer only) | OAuth 2.0 scopes, for example `["fr:idm:*"]`.                                                                                    |
| `scopeDelimiter`          | No                | Scope delimiter. Default is a space.                                                                                             |
| `userName`                | Yes (basic only)  | Username for basic auth.                                                                                                         |
| `password`                | Yes (basic only)  | Password for basic auth.                                                                                                         |
| `clientId`                | Yes (bearer only) | OAuth 2.0 client ID.                                                                                                             |
| `clientSecret`            | Yes (bearer only) | OAuth 2.0 client secret. Store it in a [secret store](../security-guide/secret-stores.html) rather than using a plaintext value. |
| `tokenEndpoint`           | Yes (bearer only) | OAuth 2.0 token endpoint URL.                                                                                                    |
| `tokenEndpointAuthMethod` | Yes (bearer only) | Must be `client_secret_post`.                                                                                                    |

|   |                                                                                                                                                          |
| - | -------------------------------------------------------------------------------------------------------------------------------------------------------- |
|   | For any request forwarded to the remote instance that includes an `X-Requested-With` header, the remote proxy sets the header value to `RemoteIDMProxy`. |
