Skip to Main Content
IBM Data and AI Ideas Portal for Customers


This portal is to open public enhancement requests against products and services offered by the IBM Data & AI organization. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:


Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,


Post your ideas

Post ideas and requests to enhance a product or service. Take a look at ideas others have posted and upvote them if they matter to you,

  1. Post an idea

  2. Upvote ideas that matter most to you

  3. Get feedback from the IBM team to refine your idea


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

IBM Employees should enter Ideas at https://ideas.ibm.com


Status Under review
Workspace Cloud Pak for Data
Created by Guest
Created on Jun 12, 2024

SSO for REST API with Windows Active Directory accounts

We have automated work that would create/run Project and Deployment jobs. 
The automation is running using Windows Active Directory accounts but current the only way for the accounts to interact with REST API is to use the actual Username+Password or to log into CPD, get the API Key through UI and use the Username+APIKey to get the Bearer token

We would like an SSO option for those accounts to retrieve the Bearer token. Everything else with using the REST API likely would work the same.

Kerberos SSO would be a known working option that other services use and we would have immediate option to implement it. Other SSO options can be suggested and it's possible to investigate if we can use them.

Needed By Quarter
  • Admin
    Ragavie Pirabaharan
    Reply
    |
    Sep 16, 2024

    Hi Martin! This is a possible solution you could try: The OAuth password grant type is supported by Bedrock IM / identitytoken API. You can pass the username and password to this API and this will return the Bedrock OAuth token. You can then call the Zen API to exchange for a Zen bearer token

  • Guest
    Reply
    |
    Jul 8, 2024

    All I can see is that both username and password has to be provided, once password has to be provided that is no longer a SSO solution.

    As an example, with Kerberos SSO, application generates a token on the users computer that it uses to authenticate to the system. No password needed for the login.

  • Admin
    Malcolm Singh
    Reply
    |
    Jul 5, 2024

    Hi Martin, It is possible to get the token using an API using the Cloud Pak for Data Platform APIs.