Example Exchange Token Federation Configurations
The following is a list of Identity Providers (IP) we’ve tested Token Exchange Federation with. Other IPs could also be used for Platform6 EX_FED but will probably require some assistance from support to get the configuration correct.
Sidetrade¶
| Property Name | Value |
|---|---|
| exfed.token.claims | sub |
| exfed.token.email.claim | identityKey |
| exfed.auto.provision.permissions.claim | roleCode |
| exfed.auto.provision.permissions.org.path | /[instance-root]/Sidetrade Roles |
| exfed.userinfo.url | https://cloud-[platform-id]-api.sidetrade.com/gateway_api_fusionconsole/fusionconsole/api/v1/augmentedCashUser |
| oidc.given.name.claim | firstName |
| oidc.family.name.claim | lastName |
| oidc.jwks.endpoint | https://cloud-[platform-id]-web-oauth.sidetrade.com/.well-known/openid-configuration/jwks |
Note
exfed.userinfo.url is used to obtain PII about the user such as email, firstname and lastname.