Run-Time Consumer Registration Scenarios
Pre-requisite: To impose an approval process, ensure that you have created a design-time, for example, the Consumer-Registration Policy, as described in the previous section.
An API provider (owner of the API) specifies the type of authentication (API key or OAuth2 token using the consumption settings) and configures a set of Evaluate * actions (using the run-time policies) to identify and authorize the consumer that request the consumption access to the metadata of the particular API. Based on the specified enforcement definitions for the API, CentraSite offers interactive user interfaces for the following four exemplary scenarios:
Is API Consumption Settings Configured? | Is an Evaluate Action Configured? | For Procedures… |
No | No | |
No | Yes | |
Yes | No | |
Yes | Yes | |