API
The API configuration module allows you to select and configure the Projects that can be accessed through the API and the Users that can access the API. The API uses Projects for access to the data model and configurations such as Filters and Scopes. Additionally the Users that have access to these Projects can be used to provide optional authentication to be allowed access to the Projects through the API.
Projects
In the API configuration module you select the Projects that can be accessed externally through the API. After saving the selection, there are specific configuration parameters for each selected Project.
| Default | Indicate whether the Project is the default Project that can be accessed through the API. This allows you to leave out the Project ID path parameter) when querying the API. |
| Authentication | Check to require authentication to access the Project through the API. |
| Translation URL | Redirect API requests to another location (e.g. a Public User Interface). |
Authentication
A request to the API requires authentication credentials of a valid User when a client tries to access a Project that requires it. The authentication procedure follows the OAuth 2.1 protocol. To allow clients access to your Project you first need to add the client to the configuration of the API. Subsequently you assign Users to the client that provide the necessary and actual authentication for access to your Projects.
Client
A client serves to identify the external requests made to your nodegoat Domain. Clients can be used by external services to make authorised requests on behalf of nodegoat Users. Clients can for instance be used to directly connect an AI application to your MCP in nodegoat.
It is also possible to manually manage Users for a client by assigning Users to a client directly (see User section below), skipping the external service doing the negotiation.
When clients are used by an external service to request authorisation on behalf of nodegoat Users, you require the automatically generated identifier and passkey (secret) for the client. The passkey can be regenerated when the passkey of the client has been compromised.
To add a client:
| Active | Specify whether the client is allowed access (active or inactive). You can change this state by editing the client. |
| Name | Enter the name/identity of the client. |
| Redirect URL | Enter the URL of the service that is to make use of the client (see documentation of the service for the URL). By default this is open and set on first successful use; any service can negotiate with the client and automatically claim the redirect URL. When the URL is set explicitly, the client is secured to only negotiate with that specific service. |
| Validity Period | Provide the default validity period Users assigned to the client are allowed access to the API through the client. Leave the validity period empty to set the default period to allow for indefinite access. You can change the default validity period by editing the client. |
User
Users are assigned to clients to provide the necessary authentication when a client accesses the API. The provided User identity configures nodegoat just like a regular nodegoat login would. Important configurations based on the User’s identity are:
- Whether the User has access to the requested Project.
- Whether the User has the required view and edit clearances to view the data.
To assign a User to a client, click 'add' at the relevant client, and:
| Active | Specify whether the client is allowed access (active or inactive) through the client. You can change this state by editing the User assignment. |
| User | Search and select the relevant User. |
| Validity Period | Provide the validity period the User is allowed access to the API through the client. Leave the validity period empty to allow for indefinite access. You can change the validity period by editing the User assignment. |
The required passkey (token) is generated automatically. Consult the API usage section to start making authenticated requests through the client with the generated User passkey (token).