Using the Universal Wallet Manager

The Universal Wallet Manager (UWaaS) supports management of administrative and custodial wallet resources.

Authentication

Secured endpoints require a bearer token in the authorization header:
Authorization: Bearer <access_token>
The proxy validates the token in accordance with the deployment configuration (for example, following command to generate a bearer token by using the access token endpoint that is available in the Blockchain Platform Manager.
curl -sS -X POST \
  "<Access Token Endpoint – fetched from Blockchain Platform Manager>" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "grant_type=password" \
  -d "client_id=<CLIENT_ID>" \
  -d "client_secret=<CLIENT_SECRET>" \
  -d "username=<USERNAME>" \
  -d "password=<PASSWORD>"
The following text shows an example response. You then use the value of access_token as the bearer token for subsequent calls.
{
  "access_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9....",
  "expires_in": 300,
  "token_type": "Bearer"
    ...
}

Authorization

UWaaS uses role-based access control. See:
User Group Group Name in OpenLDAP Description
Wallet Super Admin OBP_WALLET_SUPER_ADMIN

Permissive read/write access to ​all API resources across all organizations. Specifically:

  • Read/Write
    • All orgs
    • All users
    • All org-networks
    • All wallets
    • All policies (= rules)
Wallet Org Admin OBP_WALLET_ORG_ADMIN

Read/write access to all resources API resources scoped to that admin user’s organization.

  • Read/Write
    • Own org(s)
    • All users in own org(s)
    • All org-networks in own org(s)
    • All wallets in own org(s)
    • All policies scoped to own org(s)
Wallet Org User OBP_WALLET_ORG_USER

Restricted read access to all wallets owned by that user, and other resources scoped to that user's organization.

  • Read
    • Own wallet(s)
    • Own org(s)
    • Own user
    • Org-nets scoped to own org(s)

Quick Start

Execute your first cURL call and validate your configuration by using the following example which retrieves readiness of the application.


curl -X GET \
  "<REST_PROXY_BASE_URL>/ready" \
  -H "Authorization: Bearer <access token>" \
  -H "Accept: application/json"