Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Version History

« Previous Version 16 Next »

All services require TLS (version 1.2 or higher) for transport security. In line with industry best practices the HIMSA IdP does not allow IFRAME based usage for any kind of user interactive authentication. An X-FRAME-OPTIONS HTTP header is always returned with the value ‘SameOrigin’.

Authentication

Noah ES contains an Identity Provider that supports OAuth 2.0 and OpenId Connect. The Identity Provider (IdP) is used for Authentication.

All services require a valid token from the IdP when called.

1. Request

Parameters that must be supplied:

  • URI and port number
    • QA environment: idp.qa.eu.noah-es.com:443
    • EU Production: idp.eu.noah-es.com:443
    • US Production: idp.us.noah-es.com:443
  • ClientId: Supplied by HIMSA
  • Scope: openid profile noah.cloud.app.api
    • If relevant for your app and app registration allows: offline_access
  • Flow: Authorization Code
  • RedirectURI: IdP will redirect the client to this after successful authentication, with tokens for accessing the API. You must inform HIMSA about this, because we need to whitelist it
  • Extra options
    • culture-lcid: Culture LCID code for localizing the website

2. Response

When the client is redirected to the RedirectURI, the body in the response will contain:

  • tenantid: The tenantId that the user selected
  • RefreshToken: Must be exchanged afterwards for an access token. If using HIMSA's .NET Client this step is automated

3. Exchange refresh token for an access token

Note: This is done automatically if you are using HIMSA's .NET Client

4. Connecting to API

  • URI and port number
    • QA environment: api.qa.eu.noah-es.com:443
    • EU Production: api.eu.noah-es.com:443
    • US Production: api.us.noah-es.com:443
  • HIMSA's .NET Client:
    • Use the constructor that takes the refresh token as input

Logging off

In case a user only set up 1 account and that account is of type single sign-on, logging off will redirect the user directly to the login page. In that case it will not be possible to set up a different account.

We suggest to redirect to the account selection page of the IdP after successfully logging off. It is then important to include "forcechoose" in the query string (with any value).

  • No labels