Skip to main content
Version: v3.6.x LTS

Enabling single sign on for extending services

Enabling single sign on for extending services

Roles: system programmer, API service extender

Enabling Single Sign On (SSO) in Zowe involves configuring JWT tokens or PassTickets for secure authentication. The JWT token configuration requires setting up a custom HTTP header to store the token, thereby enhancing secure communication with southbound services.

For more information, see Enabling single sign on for extending services via JWT token configuration.

PassTicket configuration, alternatively, allows services that do not natively support JWT tokens or client certificates to authenticate via the API Gateway. This authentication process requires the activation of PassTicket support, recording the APPLID, and configuring the Zowe started task user ID. Additionally, custom HTTP headers can be set up for PassTickets and user IDs, ensuring secure and streamlined access within the Zowe ecosystem.

note

The PassTicket configuration process differs depending on whether you are setting up your first service or a subsequent service. First-time setup requires full ESM configuration, whereas onboarding subsequent services only requires setting up and permitting the new APPLID.

For more information, see Enabling single sign on for extending services via PassTicket configuration.

For details about first service configuration and second service configuration requirements, see: