Genesys Cloud - Developer Community!

 View Only

Sign Up

  • 1.  Open Messaging Questions

    Posted 13 hours ago

    We are securing our Genesys Open Messaging integration through Azure API Management and need confirmation of the authentication capabilities supported by Genesys.
    Based on the information provided and the documentation shared, it appears that Genesys supports X-Hub-Signature-256 HMAC validation for outbound webhooks, but does not support an OAuth/JWT client-credentials flow.
    Furthermore, attachment retrieval appears to accept only a URL, without a configurable Authorization header.
    Could you please confirm:

    1. Can the webhook sender obtain and send a short-lived JWT/OAuth bearer token to APIM?
    2. Can the webhook sender present a customer-managed client certificate for inbound mTLS with APIM?
    3. Can the separate Genesys attachment downloader present either an authentication header or client certificate?
    4. If these are unsupported, what is the officially recommended pattern for securing the webhook and attachment retrieval?
      For clarity, APIM supports JWT validation and mTLS, but their use depends on the Genesys clients being able to supply the token or certificate.
    5. As part of securing our Azure API Management (APIM) endpoint, could you please provide the outbound (egress) IP ranges used by Genesys when sending webhook notifications and retrieving attachments?

    Best Regards,

    Orestis.


    #PlatformAPI

    ------------------------------
    Orestis
    ------------------------------