Twisp
Authentication
Authenticating requests against the Twisp API.
Twisp authenticates GraphQL API requests with a JSON Web Token (JWT). The token must identify a principal that has a corresponding Twisp client configuration; Twisp then evaluates that client's policies to authorize the requested operation.
Request headers
Send the JWT and the Twisp account ID with every GraphQL API request:
Authorization: Bearer <JWT>
x-twisp-account-id: <Twisp account ID>
Twisp accepts tokens issued by an OpenID Connect (OIDC) provider. For OIDC tokens, the issuer in the iss claim is typically used as the principal name. Twisp can also exchange a presigned AWS STS GetCallerIdentity request for a token whose principal represents the AWS identity.
Authorization
Authentication establishes the caller's identity; client policies determine what that identity may do. A client must exist for the token's principal and have policies that allow the requested action on the requested resource. A matching DENY policy takes precedence over an ALLOW policy.
See Security and Auth for instructions on creating clients, configuring OIDC or AWS IAM principals, and defining authorization policies.
For a walkthrough using AWS-issued tokens directly, see Connecting with AWS Identity Federation.