API Connect

API Connect

Join this online group to communicate across IBM product users and experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
Expand all | Collapse all

HTTP Authorization scheme of 'bearer' is not supported for enforced APIs

  • 1.  HTTP Authorization scheme of 'bearer' is not supported for enforced APIs

    Posted Mon December 12, 2022 10:18 AM
    Hi all,

    I am using JWT based authentication to secure the API where the client application must send a JWT in the authorization header of the HTTP request. So I added a security scheme of type 'http' as described in the OpenAPI Specification as follows:
    But when I published the API, the publish failed with this message: 

    Noting that enforced APIs means that the API Connect gateway is used to enforce the APIs.

    Thanks,
    Ahmed Ashraf



    ------------------------------
    Ahmed Ashraf
    ------------------------------


  • 2.  RE: HTTP Authorization scheme of 'bearer' is not supported for enforced APIs

    Posted Mon December 19, 2022 02:41 PM

    Hello Ahmed, 

    I have escalated your question to the team and I am waiting to hear back still - in the meantime, there is a knowledge center section, linked here, that might be helpful to guide you. 

    you can also file a support ticket while we wait. I will reach out once I hear something!

    Thank you



    ------------------------------
    Gabriel Marte Blanco
    Austin TX
    ------------------------------



  • 3.  RE: HTTP Authorization scheme of 'bearer' is not supported for enforced APIs

    Posted Tue December 20, 2022 03:49 PM
    Hello Gabriel,

    I followed up the knowledge center section link that you have provided and found that I have defined the HTTP bearer security scheme as instructed. So I will file a support ticket and will update you when I get any response.

    Thanks,

    ------------------------------
    Ahmed Ashraf
    ------------------------------