Passthrough Mode

This page describes the passthrough mode (the default) for the engine REST authentication of the REST API MCP Plugin.

In passthrough mode, the validated inbound bearer token is forwarded unchanged to the engine REST API. Use this mode when the engine REST API is itself an OAuth2 resource server for the same issuer, so that both hops are protected by the same OAuth2 token.

To set up this mode:

  • Activate OAuth2. In a Spring Boot application, add cibseven-bpm-spring-boot-starter-security, which already brings Spring Security, so no further Spring Security dependency is needed.

  • Map the user id: the engine takes the CIB seven user id from the claim configured in spring.security.oauth2.resourceserver.jwt.principal-claim-name. It must match the user id stored in the engine exactly. If no claim matches, use Minted JWT Mode.

  • Disable the read-only OAuth2 identity provider, so that group and authorization resolution stays with the configured identity provider:

    camunda.bpm.oauth2.identity-provider.enabled=false
    

To make this mode safer, the engine REST API should be configured to validate the audience (aud).

On this Page: