Skip to Content
ConceptsCore ProtocolAPI Gateway

API Gateway

Single ingress for all client traffic. Spring Cloud Gateway, routes defined programmatically in GatewayConfig.java (not application.yml).

Request flow

Auth models by caller

CallerMechanismChecked where
Issuer / AdminJWT bearer tokenGateway (JwtTokenValidationGatewayFilter)
Holder / Verifier / CustodianHttpOnly cookie sessionCore Engine (not gateway-inspected)
Public endpointsNone—

Route groups

GroupPath prefixAuthBackend
Credential verify/api/v1/credentials/verify, /api/v1/verify/**PublicCore Engine
Credential issuance/api/v1/credentials/issue, /batchJWT optional (BYOK signature substitutes)Core Engine
Issuer registration & admin ops/api/v1/issuer/**, /api/v1/issuers/**Public (register) / JWT admin (approve, reject, rotate, status, SSO)Core Engine
Holder wallet/api/v1/holder/**Cookie sessionCore Engine — see Holder Authentication
Verifier/api/v1/verifier/**Public (auth) / Cookie session (profile)Core Engine — see Verifier / Employer Identity
Custodian/api/v1/custodian/**, /api/v1/custodians/**Cookie session / JWT adminCore Engine
Admin login/api/v1/admin/auth/loginPublic (issues token)Admin Console :8084
Admin (remainder)/api/v1/admin/**JWT (ADMIN/OPERATOR/VIEWER)Admin Console :8084
Admin catalog/api/v1/admin/catalog/**JWTCore Engine — routed before the blanket admin rule
Issuer portal/api/v1/portal/**JWT (issuer session)Core Engine
Fallback/api/v1/**Public / self-validatingCore Engine

LLM-backed endpoints (credential-insight, support-ask, issuer-kyc-document, admin/audit-logs/nl-search) carry their own tighter rate limits — see LLM Integration.

CORS

Dev-server origins allowed by default: issuer-portal (5173), verifier-portal (5174), admin-console (5175), credential-wallet (5176), custodian-portal (5178). landing (5177) doesn’t call the API, so it needs no CORS entry. Deployed environments override the allowlist per-frontend with each ${DOMAIN} subdomain, since every MFE sits behind the nginx reverse proxy there instead of a raw Vite dev port.

Admin Console integration

PropertyValue
Port (REST)8084
Schemaconsole — independent from operational schemas
AuthAdmin JWT (ADMIN, OPERATOR, VIEWER)
Rate limit10 req/min per admin user

Covers admin user management, system configuration, audit logs (including natural-language search), live container log tailing, network stats, and system health — all under /api/v1/admin/**.

Observability

  • Every routed verification request triggers a background audit log entry in core.audit_logs, surfaced to the holder via GET /api/v1/holder/access-logs.
  • X-Correlation-ID propagates Gateway → Core Engine → microservices for end-to-end tracing.