Workspace Environment Management™ REST APIs

On-premises deployment of REST APIs for Workspace Environment Management™

The Workspace Environment Management (WEM) on-premises API runs on your local WEM web console server (HTTPS, default port 443) and does not use Citrix Cloud™ Identity and Access Management (IAM).

Therefore, instead of using a Citrix Cloud bearer token, you submit your credentials to the login API to obtain a session token, and then present that token on every subsequent request. For information about the WEM service (cloud) deployment, see About REST APIs in Citrix Workspace Environment Management.

Log in

Submit credentials to obtain a session token.

POST /services/wem/onPrem/LogIn
<!--NeedCopy-->

Credentials are provided via HTTP Basic Authentication: base64-encode Username:Password and include it in the Authorization header. For example, if using Active Directory credentials, the user name format is DOMAIN\Username.

The following is an example request:

POST https://<wem-server>/services/wem/onPrem/LogIn
Authorization: Basic <base64(Username:Password)>
Accept: application/json
<!--NeedCopy-->

You might retrieve the following results:

{
  "sessionId": "A3GX7K2..."
}
<!--NeedCopy-->

The session token expires one hour after it is issued. Log in again to obtain a new one.

Usage

Include the sessionId from the login response in the Authorization header of all subsequent requests using the session scheme:

Authorization: session <sessionId>
<!--NeedCopy-->

The following is an example request that queries all configuration sets:

GET https://<wem-server>/services/wem/sites
Authorization: session A3GX7K2...
Accept: application/json
<!--NeedCopy-->

You might retrieve the following results:

{
  "items": [
    {
      "id": 1,
      "name": "Default Site"
    },
    {
      "id": 2,
      "name": "Branch Office"
    }
  ]
}
<!--NeedCopy-->

Permissions

The login account must have the required WEM RBAC permissions in the WEM infrastructure database.

Before version 2611.1.0.1

The account must be a Global Full-Access Administrator as defined in the legacy WEM administration console. To view or manage these accounts, open the legacy console and navigate to Administration.

See: WEM Administration — User Interface Description

Note: When you first created the WEM database, a Global Full-Access Administrator group was automatically configured. Members of that group can log in without any additional setup.

Version 2611.1.0.1 and later

A new RBAC mechanism is available. Administrators can now define granular permissions, specifying which accounts have access to which operations and which scopes. Ensure your login account has been granted at least one scope. The session token you receive at login only grants access to resources within the scopes assigned to that account.

Resources
Workspace Environment Management™ REST APIs OpenAPI Specification
Copy Download
On-premises deployment of REST APIs for Workspace Environment Management™

In this article