Authentication

Authenticating requests against the Twisp API.

Twisp authenticates GraphQL API requests with a JSON Web Token (JWT). The token must identify a principal that has a corresponding Twisp client configuration; Twisp then evaluates that client's policies to authorize the requested operation.

Request headers

Send the JWT and the Twisp account ID with every GraphQL API request:

Authorization: Bearer <JWT>
x-twisp-account-id: <Twisp account ID>

Twisp accepts tokens issued by an OpenID Connect (OIDC) provider. For OIDC tokens, the issuer in the iss claim is typically used as the principal name. Twisp can also exchange a presigned AWS STS GetCallerIdentity request for a token whose principal represents the AWS identity.

Authorization

Authentication establishes the caller's identity; client policies determine what that identity may do. A client must exist for the token's principal and have policies that allow the requested action on the requested resource. A matching DENY policy takes precedence over an ALLOW policy.

See Security and Auth for instructions on creating clients, configuring OIDC or AWS IAM principals, and defining authorization policies.

For a walkthrough using AWS-issued tokens directly, see Connecting with AWS Identity Federation.