Skip to main content
tools
Tools

Client Credentials 1.0.1

  • OAuth

The OAuth 2.0 Client Credentials authorization process enables consumers to authenticate themselves using client credentials and receive an OAUTH 2 access token. This token is used when making calls to an API product on the ABN AMRO API gateway.

Tutorial

How this authorization methods works

  1. A consumer requests an access token by sending their credentials using mutual TLS to the authentication server.
  2. The authentication server receives the credentials and authenticates the consumer based on client ID, public key, private key and certificate chain and provides an access token.
  3. The access token is used when calling an API on the ABN AMRO API gateway.

Mutual TLS (TLSMA)

This authorization process uses mutual TLS to authenticate the consumer based on an x.509 certificate. The consumer must send a public key, private key, and certificate chain in the request to prove their identity.

In Mutual TLS, the server authenticates using a server certificate. The consumer must send the certificate as proof of identity. The consumer is configured to accept one certificate for authentication which is used to set up TLS-MA.

In the TLSMA process, a verification check is performed on the issuer DN and the subject DN of the certificate. Expired certificates can be renewed without updating the configuration of your client.

Important: When renewing a certificate, SubjectDN must be the same as the value that was used in the previous request. The certificate must also be signed by an ABN AMRO approved certificate authority.

Development Guidelines

To prevent false positives and the blocking of legitimate traffic, Akamai developed some guidelines and standards to detect the bot requests.

Why: Akamai is able to detect automated processes connected to your application. If we do not know what they are, Akamai can start blocking this traffic.

If you are using traffic that potentially can trigger bot detection, please contact the Network Security Services team by sending an email to nss@nl.abnamro.com so we can discuss alternatives.

What: Use standardized HTTP headers, so Akamai can whitelist this bot detection.

How to mitigate: Set the following user-agent header while requesting Token.

  • User-Agent: Anything that is specific (no development tools etc)
  • from: contact email address

Approved certificate authorities

Certificates used in the client credentials authorization process must be signed by an ABN AMRO approved Certificate Authority (CA). Certificate authorities that are not in the list of supported certificate authorities will not be accepted. If your certificate authority is not in the list, see Support.

Note: To add a new certificate authority, a minimum of 3 to 4 weeks is required to complete the approval procedure.

CA list

To view the most recent list of approved certificate authorities, execute the following command:

openssl s_client -connect auth-mtls-trustedcerts.abnamro.com:443 -servername auth-mtls-trustedcerts.abnamro.com

Check if your CA is approved

To check if your CA is ABN AMRO approved, execute the following cURL sample using the attributes below.

  • certificate - application certificate location
  • private_key - private key location
  • cacert - ca certificate chain location
    curl -X GET \
    https://auth-mtls.abnamro.com/.well-known/openid-configuration \
    --cert ./certificatefile.crt \
    --key ./private_key.key \
    --cacert ./ca_certificate_chain.pem

If authentication is successful you will receive a 200 - OK message. This indicates that the attempt for mutual authentication is successful and that the issuer (cacert) has been accepted.

Requirements

To use this authorization method, you must have:

  • An account and an application in the ABN AMRO Developer Portal. For more information, go to Basics and complete step 2 and 3.
  • An approved certificate. For more information, see Approved certificate authorities.

How to use this API

This instruction describes how to authenticate yourself based on client credentials and obtain an access token.

Note: This process uses the Postman API Client.

Step 1 - Configure Postman

  1. Open Postman.
  2. In the top left of the screen, click File > Settings > Certificates > Add Certificate.
  3. In the Hostname field, enter https://auth-mtls.abnamro.com and the port number as: 443.
  4. In the CRT file field, Click Select File and add your CRT file.
  5. In the KEY file field, Click Select File and add your KEY file.

    Optionally: If you import a p12 or pfx file, you do not need to complete the above 2 steps.

  6. In the Passphrase field, passphrase of the KEY file.
  7. Click on a request, Click Authorization.
  8. In the Type dropdown field, select Inherit auth from the parent.

Step 2 - Request an access token

To request an access token, you must send your credentials to the authentication server using mutual TLS. The authentication server receives the credentials and authenticates you based on client ID, public key, private key and certificate chain, and provides an access token.

To request an access token, see the requestAccessToken operation.

TelephoneNeed help?

Check the frequently asked questions or contact us. We are happy to help.
 

Get support Learn the basics