Posted: 10 Oct 2017 18:24 EDT Last activity: 16 Oct 2018 12:03 EDT
Custom OAuth2 Authentication Service
We are looking to authenticate Pega users via an external system (Azure B2C). The external system exposes a login REST API that takes credential parameters and returns an OAuth2.0 token if authentication is successful.
I'm looking at using the OAuthAuthentication authentication service option. Within this service, there is an activity called pzOAuth2AuthenticationActivity. From what I can see, there is no step which makes a call out to the external system for authentication.
Has anyone implemented a similar authentication pattern? Do I need to add a REST connect step to the activity to call my login REST API or am I missing something?
Thanks in advance.
**Moderation Team has archived post**
This post has been archived for educational purposes. Contents and links will no longer be updated. If you have the same/similar question, please write a new post.
Hi Bill, are these pega end users browser based users?
please correct me if my understanding is wrong,
when an end user accesses the pega application url via browser, user is presented with the login screen from pega application. once the user enters the credentials, those details will be taken by pega and posted to external system(Azure B2C). external system authenticates the user & sends back the token to pega. Pega then validates the token and allows the end user to login?
ok. Since there is no out of the box example, may be you could 'SaveAs' OOTB authentication activity rule to your application rule set, refer the newly created new in the authentication service rule. I don't see a reason why your approach of creating an explicit rest connector from the authentication activity would not work.