Overview of Security Policies

This section explains the security policies supported by TIBCO API Exchange Gateway software.

TIBCO API Exchange Gateway allows you to secure a facade operation or a target operation using various types of security policies. This allows you to apply the policy to the incoming messages received from the service consumers and also apply the policy to the outgoing messages forwarded to the service providers. You can apply the policies at the endpoints of facade or target operations. See Types of Security Policies for the details on the supported policies.

The figure below illustrates the security policy enforcement points in the standard request processing pipeline.

Security Enforcement EndPoints