Security
OIDC, roles, gateway limits, CORS, and API keys.
Connect authenticates with your OIDC IdP (Authentik in the reference stack) and authorizes with Developer / Operator / Admin. See Authentication and Roles.
Gateway
APISIX validates JWT on /api/* (except HMAC ingest), rate-limits, and caps body size. Invalid JWT → 401. Rate limit → 429. Role failure on the platform → 403.
HMAC partner ingest is a separate route: signature instead of OIDC.
CORS
CONNECT_CORS_ALLOWED_ORIGINS is an explicit list. No wildcards. Credentials allowed for listed origins only. Docs (docs.connect.intronsoft.com) and Portal must be on that list for Try-it and the SPA.
Headers
The platform sets HSTS, XSS protection, frame-ancestors 'none', and a strict CSP default.
API keys
Machine GETs on published Experience paths accept X-API-KEY from hashed catalog_consumer keys (or laptop CONNECT_API_KEYS). Ops stays JWT. Revoke by rotating/revoking the consumer.
Docs access
Experience guides and EAPI try-it are public. APIs → System is SSO-gated at the edge. Try-it OAuth is separate from that page gate.
If this fails
| Symptom | Cause |
|---|---|
| Browser CORS error on Try-it | Docs origin missing from CONNECT_CORS_ALLOWED_ORIGINS |
| Try-it 401 after Authorize | Redirect URI not registered on the intron-connect client |