GIW Identity Platform — API documentation
Generated from the repository at image build time. Everything here works offline.
POC · LOCAL DEMO ONLY. Nothing in this documentation is a production contract. Direct Grant / password grant is a POC-only implementation; the browser / Authorization Code + PKCE path is retained as production candidate. See Auth Strategy.
API reference
| What | Where |
|---|---|
| Interactive OpenAPI reference — every endpoint, schema and example | reference.html |
| Raw specification, for codegen and client tooling | openapi.yaml |
Companion documents
Start here
| Document | Source |
|---|---|
| API Overview | api/API-OVERVIEW.md |
| API Matrix | api/API-MATRIX.md |
| Sequence Diagrams | api/API-SEQUENCES.md |
Contract
| Document | Source |
|---|---|
| Keycloak Integration (EN) | api/KEYCLOAK-INTEGRATION-SPEC.vi.md |
| DMN Decisions (EN) | api/DMN-DECISION-SPEC.vi.md |
| Loyalty Integration | api/LOYALTY-INTEGRATION-SPEC.md |
| giw-admin Module | api/GIW-ADMIN-MODULE-SPEC.md |
| Token Claims | api/TOKEN-CLAIMS.md |
| Error Catalog | api/ERROR-CATALOG.md |
Security & privacy
| Document | Source |
|---|---|
| Data Classification | api/DATA-CLASSIFICATION.md |
| API Security | api/API-SECURITY.md |
| Auth Strategy | docs/AUTH-STRATEGY.md |
Review
| Document | Source |
|---|---|
| Review Checklist | api/API-REVIEW-CHECKLIST.md |
Operate
| Document | Source |
|---|---|
| Test Guide (EN) | docs/TEST-GUIDE.vi.md |
| giw-admin + Camunda Modeler (EN) | docs/GUIDE-GIW-ADMIN.vi.md |
| Runbook | docs/RUNBOOK.md |
| Environments | docs/ENVIRONMENTS.md |
The four authorities
| System | Authority over | Never |
|---|---|---|
| Keycloak (Galaxy ID) | Authentication | Opens the network · decides entitlement |
| HR Verification API | Employment status — a gate | Returns a profile · is a system of record for identity |
| Loyalty API | Member tier — enrichment only | Blocks access. An outage costs a benefit, never a connection |
| DMN Decision Service | Rule evaluation | Issues entitlements · persists anything |
| Entitlement Service | Authorization — what access is allowed | Enforces · creates sessions |
| Session Service | Enforcement — access state | Decides. grant without an entitlementId is 422 |
| Wi-Fi Portal / BFF | Orchestration and presentation | Decides anything |
Running services
| Service | Local URL | Role |
|---|---|---|
| Wi-Fi Portal | http://localhost:3000 | The demo itself |
| API documentation | http://localhost:3004 | This site |
| Keycloak admin | http://localhost:8080 | Galaxy ID — identity |
| Mock HR API | http://localhost:3001 | Employment status — a gate |
| Mock Loyalty API | http://localhost:3006 | Member tier — enrichment only |
| Entitlement Service | http://localhost:3002 | Authorization — what is allowed |
| DMN Decision Service | http://localhost:3005 | Rule evaluation |
| Session Service | http://localhost:3003 | Enforcement — access state |
Every port binds to 127.0.0.1. Nothing is reachable from the LAN or the Internet.