Oracle Transactional Business Intelligence Idea Lab

Welcome to the Oracle Analytics Community: Please complete your User Profile and upload your Profile Picture

Enable JWT token-based authentication for BIP web service calls

8
Views
2
Comments

Currently, to retrieve the BIP output of a seeded ESS job via BIP web services, we use the endpoint xmlpserver/services/v2/ScheduleService?wsdl. However, this approach requires sending the username and password within the payload body, which is not a recommended or secure practice. Is it possible to enable JWT-based authentication for BIP web service calls to enhance security and align with best practices?

3
3 votes

Submitted · Last Updated

Comments

  • Prithvi_Raj
    Prithvi_Raj Rank 3 - Community Apprentice

    This will be useful for securing WSDL access to BIP Web Services. In our production accounts, only token-based access is permitted.

  • John Chan
    John Chan Rank 2 - Community Beginner

    I support this also as using basic authentication goes against our design principles especially when Oracle Fusion REST API can use JWT Tokens so why cant BIP web service. It increases risk as we have to change the Production password whenever someone leaves our organisation. Also for auditing and meeting our password policies, then we have to change the password several times a year.