API Authentication Methods
The TSB supports three different authentication methods:
- JWT tokens - JWTs are issued by the Primus HSM (firmware v3.2.11 or later)
- Mutual TLS (mTLS)
- Traditional API keys
Using these methods you can control access to the REST API. It is possible to combine these methods, for example to require both mTLS and an API key.
tip
Comparison
- JWTs are a secure, general-purpose authentication mechanism. JWTs are mandatory in CloudHSM. On-premise, a single TSB instance can serve multiple HSM partitions with HSM-issued JWTs.
- mTLS provides strong bi-directional authentication, securing the underlying TLS channel. This prevents unauthenticated users from even establishing a TLS connection, let alone make API requests.
- API keys enable fine-grained access control. You can issue API keys that are scoped only to certain operations, such as key management, key usage, or SKA approval.
Mobile Apps
The endpoints that are commonly called by mobile apps (such as SKA authorization apps) have a separate API authentication mechanism. For details, please see this tutorial.