What are you trying to build?
Migrate jXchange Authentication from WS-Security to OAuth 2.0 for iPay
Q1
Can one client ID be authorized for multiple institution routing IDs? Unlike host-jxchange (single INST_RTG_ID env), bill-pay-ipay-api can serve several routing IDs from one deployment — the Inst Routing Id Mapping configurable property maps a user identifier to an InstRtId, substituted into ns:InstRtld per call. JH authorizes a client to an institution.
Q2
What is the DMZ hostname under OAuth? Neither the email nor the docs name one — both give only jx.jackhenry.com. Gates story 3.
Q3
Why does the DMZ still accept WS-Security, and when will the cutover actually be enforced? Determines how much runway our test environment has.
Q4
Is the SilverLake DMZ tenant already authorized for the BilPay messages? Or does iPay need its own DMZ authorization? A static public key is acceptable for DMZ, so this is the only thing between us and a DMZ proof-of-concept.
Q5
Confirm the amendment model: reuse the FI’s existing client ID and authorize the BilPay* operations, rather than issuing a second client.
[Return to Manage Case](javascript:submitAction_win0(document.win0,‘JHA_CASE_SS_RPT_RETURN_TO_CASE’)![]()
Environment
- Product or API: iPay
- Environment: All
- Platform: Lumin Digital
- Authentication flow: OAuth 2.0 for iPay
- Documentation consulted: SOAP Authentication Update | jXchange - SOAP API | Jack Henry Docs
What did you try?
Just researching at this time
What happened?
- Dev has some questions regarding the SOAP Authentication Update
Safe-posting confirmation
- I removed tokens, secrets, private keys, passwords, SSNs, account
numbers, customer data, and institution-confidential configuration.