問題文
A retailer already runs an authorization server that issues OAuth 2.0 access tokens for its partner program. The retailer now wants its Anypoint-managed APIs to accept those tokens. An engineer assumes Anypoint Platform will have to issue its own tokens as well. What is the correct division of responsibilities?
選択肢
- Anypoint Platform issues its own tokens, the retailer registers the external provider as a fallback, and each API accepts whichever token arrives
- The external provider issues the tokens, the retailer registers it as the identity provider for staff sign-in, and a token enforcement policy on each API validates the token that arrives
- Anypoint Platform issues its own tokens for the managed APIs, the retailer maps each external token to one of them, and a policy on each API validates the mapped token
- The external provider issues and owns the tokens, the retailer registers it as the client provider for the business group, and a token enforcement policy on each API validates the token that arrives