GIW Identity Platform — API documentation

Generated from the repository at image build time. Everything here works offline.

POC · LOCAL DEMO ONLY. Nothing in this documentation is a production contract. Direct Grant / password grant is a POC-only implementation; the browser / Authorization Code + PKCE path is retained as production candidate. See Auth Strategy.

API reference

WhatWhere
Interactive OpenAPI reference — every endpoint, schema and examplereference.html
Raw specification, for codegen and client toolingopenapi.yaml

Companion documents

Start here

DocumentSource
API Overviewapi/API-OVERVIEW.md
API Matrixapi/API-MATRIX.md
Sequence Diagramsapi/API-SEQUENCES.md

Contract

DocumentSource
Keycloak Integration (EN)api/KEYCLOAK-INTEGRATION-SPEC.vi.md
DMN Decisions (EN)api/DMN-DECISION-SPEC.vi.md
Loyalty Integrationapi/LOYALTY-INTEGRATION-SPEC.md
giw-admin Moduleapi/GIW-ADMIN-MODULE-SPEC.md
Token Claimsapi/TOKEN-CLAIMS.md
Error Catalogapi/ERROR-CATALOG.md

Security & privacy

DocumentSource
Data Classificationapi/DATA-CLASSIFICATION.md
API Securityapi/API-SECURITY.md
Auth Strategydocs/AUTH-STRATEGY.md

Review

DocumentSource
Review Checklistapi/API-REVIEW-CHECKLIST.md

Operate

DocumentSource
Test Guide (EN)docs/TEST-GUIDE.vi.md
giw-admin + Camunda Modeler (EN)docs/GUIDE-GIW-ADMIN.vi.md
Runbookdocs/RUNBOOK.md
Environmentsdocs/ENVIRONMENTS.md

The four authorities

SystemAuthority overNever
Keycloak (Galaxy ID)AuthenticationOpens the network · decides entitlement
HR Verification APIEmployment status — a gateReturns a profile · is a system of record for identity
Loyalty APIMember tier — enrichment onlyBlocks access. An outage costs a benefit, never a connection
DMN Decision ServiceRule evaluationIssues entitlements · persists anything
Entitlement ServiceAuthorization — what access is allowedEnforces · creates sessions
Session ServiceEnforcement — access stateDecides. grant without an entitlementId is 422
Wi-Fi Portal / BFFOrchestration and presentationDecides anything

Running services

ServiceLocal URLRole
Wi-Fi Portalhttp://localhost:3000The demo itself
API documentationhttp://localhost:3004This site
Keycloak adminhttp://localhost:8080Galaxy ID — identity
Mock HR APIhttp://localhost:3001Employment status — a gate
Mock Loyalty APIhttp://localhost:3006Member tier — enrichment only
Entitlement Servicehttp://localhost:3002Authorization — what is allowed
DMN Decision Servicehttp://localhost:3005Rule evaluation
Session Servicehttp://localhost:3003Enforcement — access state

Every port binds to 127.0.0.1. Nothing is reachable from the LAN or the Internet.

GIW POC Identity Platform · local demo · not production · generated from the repository