post
https://api.openasapp.net/v1/api/webServices/validateUserIdentity
Validate the identity of a user given a X-OAA-USER-IDENTITY token received from /webServices/tunnel.
Recent Requests
Log in to see full request history
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||
Loading…
Exchanges a X-OAA-USER-IDENTITY token received from /webServices/tunnel for information about the user having called the web service.
In order to prevent spoofing, X-OAA-USER-IDENTITY tokes are bound to the service they were issued for. This is achieved by comparing your webService URL with the webService URL the token was issued for before returning the validated user identity. If an attacker calls your web service with a spoofed token from another service, the user identity validation fails which in turn prevents your web service from revealing sensitive user specific information to the attacker.
