On-premises deployment of REST APIs for Workspace Environment Management™
The Workspace Environment Management (WEM) on-premises API runs on your local WEM web console server (HTTPS, default port 443) and does not use Citrix Cloud™ Identity and Access Management (IAM).
Therefore, instead of using a Citrix Cloud bearer token, you submit your credentials to the login API to obtain a session token, and then present that token on every subsequent request. For information about the WEM service (cloud) deployment, see About REST APIs in Citrix Workspace Environment Management.
Log in
Submit credentials to obtain a session token.
POST /services/wem/onPrem/LogIn
<!--NeedCopy-->
Credentials are provided via HTTP Basic Authentication: base64-encode Username:Password and include it in the Authorization header. For example, if using Active Directory credentials, the user name format is DOMAIN\Username.
The following is an example request:
POST https://<wem-server>/services/wem/onPrem/LogIn
Authorization: Basic <base64(Username:Password)>
Accept: application/json
<!--NeedCopy-->
You might retrieve the following results:
{
"sessionId": "A3GX7K2..."
}
<!--NeedCopy-->
The session token expires one hour after it is issued. Log in again to obtain a new one.
Usage
Include the sessionId from the login response in the Authorization header of all subsequent requests using the session scheme:
Authorization: session <sessionId>
<!--NeedCopy-->
The following is an example request that queries all configuration sets:
GET https://<wem-server>/services/wem/sites
Authorization: session A3GX7K2...
Accept: application/json
<!--NeedCopy-->
You might retrieve the following results:
{
"items": [
{
"id": 1,
"name": "Default Site"
},
{
"id": 2,
"name": "Branch Office"
}
]
}
<!--NeedCopy-->
Permissions
The login account must have the required WEM RBAC permissions in the WEM infrastructure database.
Before version 2611.1.0.1
The account must be a Global Full-Access Administrator as defined in the legacy WEM administration console. To view or manage these accounts, open the legacy console and navigate to Administration.
Note: When you first created the WEM database, a Global Full-Access Administrator group was automatically configured. Members of that group can log in without any additional setup.
Version 2611.1.0.1 and later
A new RBAC mechanism is available. Administrators can now define granular permissions, specifying which accounts have access to which operations and which scopes. Ensure your login account has been granted at least one scope. The session token you receive at login only grants access to resources within the scopes assigned to that account.