Avaya Workspaces for Call Center Elite requires configuration of token-based access to UCA REST APIs. After the configuration has been done, all REST requests must contain a valid token within the request header or the requests are rejected. Token-based access affects Avaya Control Manager management of the Avaya Workspaces for Call Center Elite solution and agent logins.
Token enforcement requires that the client of the REST API first requests a token from the Avaya Breeze® platform Authorization Service. The client sends a digitally-signed token request to the service with a list of objects that it wants to access. If the Authorization Service recognizes the client and grants access to the resource, the service returns a signed token. The client uses this token in subsequent calls to the target REST service. The service endpoint checks the validity of the token on each request and processes a request only if the token is valid.
For token-based access to work, perform the following procedures:
-
Install signed certificates on the Avaya Control Manager deployment.
-
Install the root certificate from the Avaya Breeze® platform cluster hosting the Authorization service as a trusted root certificate authority on the Avaya Control Manager application server.
-
Import the Avaya Control Manager public certificate into the Authorization clients list so that the Authorization service recognizes token requests from the Avaya Control Manager server.
-
Assign Grants to the Avaya Control Manager client to define the list of resources that can access the Avaya Control Manager server.
-
Enable token-based access in Avaya Control Manager.
-
Configure the Avaya Breeze® platform assigned Client ID for Avaya Control Manager in Avaya Control Manager.
-
For more information, please refer
Configuring Avaya Control Manager documentation available on the Avaya Support website at
https://support.avaya.com