Hi @Maycon Belfort,
Thank you for your clear explanation and for confirming that maxauth is no longer supported in Maximo Manage under MAS 9.1.
Using MXAPIAPIKEY with an Admin API key for the API key lifecycle makes sense for creating, listing, and deleting Manage API keys.
I have one follow-up question regarding the user authentication flow.
In Maximo 7.6, we used to validate the user credentials by calling Maximo APIs with:
Before generating the API token.
Since maxauth is not supported anymore in MAS Manage, what is the recommended supported approach to validate an interactive user's credentials before creating a Manage API key for that user through MXAPIAPIKEY?
Should the credential validation be done only through MAS OIDC/SAML authentication flow, or is there any supported MAS/Manage REST endpoint that can validate username/password credentials?
Our goal is to allow a custom application to authenticate users and then generate/revoke their Manage API keys programmatically without manual intervention from the Maximo UI.
Thanks again for your support.