Key concepts

Understand the key concepts used when configuring Enterprise Connector for API Gateway.

Enterprise Connector

Enterprise Connector runs in your on-premises environment and establishes an outbound connection to the cloud-hosted API Gateway. This eliminates the need for inbound network access to your on-premises systems.

Hybrid Service

The API Gateway Hybrid Service runs within Enterprise Connector. It proxies requests, applies authentication, and manages the OAuth 2.0 token lifecycle for outbound requests.

Enterprise location

An enterprise location is provisioned in ION and represents your on-premises environment. Enterprise Connector is deployed to a specific location, and multiple endpoints can share the same location.

Target Security

Target Security defines how Enterprise Connector authenticates when calling the target endpoint.

Policy Description
Anonymous No authentication is applied to outbound requests.
API Key A static key is sent as a header or query parameter.
Basic A user name and password are sent as HTTP Basic credentials.
JWT Target Authentication A signed JSON Web Token is sent as a Bearer token.
OAuth 1.0a OAuth 1.0a signed requests that use consumer key, consumer secret, and token credentials.
WS-Security Username Token SOAP-based user name token authentication for WS-Security-protected services.
OAuth 2.0 A Bearer token is acquired from an external authorization server by using the Client Credentials or Resource Owner Password Credentials (ROPC) grant type. The Hybrid Service automatically manages token acquisition, caching, refresh, and injection.

OAuth 2.0 grant types

Grant type Use case Required credentials
Client Credentials Machine-to-machine authentication without user context. Token URL, Client ID, Client Secret, and optionally Scope.
Resource Owner Password Credentials (ROPC) Authentication on behalf of a specific user by using stored credentials. Token URL, Client ID, Client Secret, Username, Password, and optionally Scope.