Skip to main content

Authentication

Every request to an Andgo API passes through the gateway, which authenticates the caller before the request ever reaches a backend. This page explains the model and how to present credentials.

The model​

You present a token issued by your identity provider. The gateway's consolidator validates it, enriches the request with your tenant tier and group membership, and re-mints a single internal token that the backend trusts. Backends never see your original credential — they validate the internal token against the portal's OIDC discovery document.

Presenting your token​

Send your token in the Authorization header as a bearer credential:

GET /candidates HTTP/1.1
Host: hsms.example.andgosystems.net
Authorization: Bearer <your-token>

What the backend sees​

The internal token carries claims the backend uses for authorization:

ClaimMeaning
issThe portal's issuer — backends validate against its discovery doc
tenantYour resolved tenant identifier
tierYour tenant's tier
groupsGroup memberships used for operation-level permissions

The gateway authenticates and enriches; it does not decide what you're allowed to do. Each backend decides which tenant/tier/group combinations may perform which operations.