...
Four different App registrations are used:
...
1. EG Zynergy Partners App
...
- EG Zynergy Partners ApiService
- EG Zynergy Partners IntegrationApiService
- Scope:
User.ReadMicrosoft Graph
Purpose:
- User authentication via Microsoft Entra External ID (CIAM) - issues user tokens
- Swagger authentication for ApiService and IntegrationServiceAPI - issues user tokens
- Frontend Blazor WebAssembly application identity
...
- EGU.PartnerPortal.ApiService (not needed??)
- EG Zynergy Partners IntegrationApiService
- Microsoft Graph
Purpose:
- Shared service-to-service authentication identity
- Used by both ApiService and IntegrationServiceAPI for service calls
...
- EG Zynergy IntegrationApiService
- Microsoft Graph
Purpose:
- ApiService backend API identity
- Service-to-service authentication when ApiService calls IntegrationServiceAPI
- Validates incoming tokens from Partner Portal App, IntegrationServiceAPI, and Partner Portal API
- Backend operations for Graph API, such as inviting users, managing groups etc.
...
- EG Zynergy Partners ApiService
- EG Zynergy Partners IntegrationApiService
- Microsoft Graph
- User.Read
Purpose:
- IntegrationApiService identity
- Service-to-service authentication when IntegrationApiService calls ApiService
- Validates incoming tokens from Partner Portal App, ApiService, Partner Portal API, and WCF service static tokens
...
| App Registration | Client ID | Token Type | Purpose | ||
|---|---|---|---|---|---|
| EG Zynergy Partners API | 39a142a0-3e9e-4c29-8f22-f17d0fa537d4 | Partner Portal App | 84c38b43-12e4-4c26-8292-8910d79aa532 | User tokens | Frontend app & Swagger authentication |
| Partner Portal EG Zynergy Partners API | 93bc5b977412b4a0-73e59785-48aa41cb-a6b69b63-703b78284351a61955334f3d | Service tokens | Shared service-to-service identity | ||
| EG Zynergy Partners ApiService | 4dad5d62 e85dc5b1- dc8cf01b- 437845bd- 8bd0b48d- ae736a4d73fe08f50ee2e160 | Service tokens | ApiService backend identity | ||
| EG Zynergy Partners IntegrationApiService | ef383bd8-146d-498d-a77b-afe4d730b6fe | IntegrationServiceAPI | bd5100ee-af63-4880-8c60-47d4207d60c1 | Service tokens | IntegrationServiceAPI identity |
...

