Authentication
Every request to an Andgo API passes through the gateway, which authenticates the caller before the request ever reaches a backend. This page explains the model and how to present credentials.
The model
You present a token issued by your identity provider. The gateway's consolidator validates it, enriches the request with your tenant tier and group membership, and re-mints a single internal token that the backend trusts. Backends never see your original credential — they validate the internal token against the portal's OIDC discovery document.
Presenting your token
Send your token in the Authorization header as a bearer credential:
GET /candidates HTTP/1.1
Host: hsms.example.andgosystems.net
Authorization: Bearer <your-token>
What the backend sees
The internal token carries claims the backend uses for authorization:
| Claim | Meaning |
|---|---|
iss | The portal's issuer — backends validate against its discovery doc |
tenant | Your resolved tenant identifier |
tier | Your tenant's tier |
groups | Group memberships used for operation-level permissions |
The gateway authenticates and enriches; it does not decide what you're allowed to do. Each backend decides which tenant/tier/group combinations may perform which operations.