{"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"set-up-and-configure-the-apigee-proxy","__idx":0},"children":["Set up and configure the Apigee proxy"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This topic provides instructions on how to set up and configure the Apigee proxy."," ","Redocly's ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs-legacy/developer-portal/guides/apigee-integration-portal/enable-ui-components"},"children":["Apigee UI components"]}," require an Apigee proxy to be able to enable developers to ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs-legacy/developer-portal/guides/apigee-integration-portal/manage-apps-keys"},"children":["manage apps and keys"]},"."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info","name":"Note"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This topic is for organization owners or administrators responsible for managing Apigee."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This proxy can:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["authenticate users (verify IDP token),"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["create developers in Apigee,"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["allow access to routes needed only for managing developer applications and keys for a specific developer,"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["forbid all other routes, and"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["be extended with any custom case-specific logic (such as logging, security, notifications, or more)."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"prerequisites","__idx":1},"children":["Prerequisites"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Connect an OpenID Connect (OIDC) ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs-legacy/settings/identity-providers"},"children":["identity provider"]},"."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For Apigee X you need to create a special service account in Google Cloud Console."]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Use the following tutorial: https://cloud.google.com/apigee/docs/hybrid/v1.2/sa-about"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Use Apigee Organization Admin permission and save a JSON key."]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For Apigee Edge you need to create a service user account."]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"task-1-upload-proxy-bundle-to-apigee","__idx":2},"children":["Task 1: Upload proxy bundle to Apigee"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Download the Apigee X or Apigee Edge proxy bundle zip file from ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Settings"]}," > ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["API gateways"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To upload the proxy bundle to your Apigee account:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Log in to Apigee (Edge or X), and navigate to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Develop > API Proxies"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["On the Proxies page, select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["+Proxy"]}," to display the ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Create proxy"]}," page."," ",{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/content-assets/add-proxies-852b1655587e1b90.png","alt":"Add Proxy","title":"#display=block;margin=auto;width=600px;"},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["From the list of templates, select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Upload proxy bundle"]},"."," ",{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/content-assets/api-proxy-createlist-4e032259a782a29e.png","alt":"Create proxy list","title":"#display=block;margin=auto;width=600px;"},"children":[]}," ","The ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Upload proxy bundle"]}," page displays."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Drag and drop or click to upload the proxy bundle for your Apigee deployment type. Make sure to first download the bundle from the Redocly app on the \"Settings\" -> \"API Gateways\" page."," ","The name field is automatically populated from the proxy bundle zip file."," ",{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/content-assets/upload-proxy-bundle-874ddf45236ae293.png","alt":"Upload proxy","title":"#display=block;margin=auto;width=600px;"},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Next"]},". The selected proxy bundle is uploaded and a Summary page displays."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create"]}," to upload the proxy bundle. A confirmation message displays and your proxy is uploaded successfully."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"task-2a-set-up-key-value-map-information-for-apigee-edge","__idx":3},"children":["Task 2a): Set up key value map information for Apigee Edge"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["After uploading the proxy bundle, create key value maps and set up the system user credentials."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To create key value maps and set up user credentials:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["From Apigee Edge, navigate to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Admin > Environments > Key Value Maps"]},". The Key value maps page displays."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["+Key value map"]}," to display the ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Add key value map"]}," dialog."," ",{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/content-assets/add-key-value-map-af47c5af1187cbb3.png","alt":"Add Key value map","title":"#display=block;margin=auto;width=600px;"},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Enter a name for the key value map, select the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Encrypted"]}," check-box."," ",{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/content-assets/key-value-map-added-1b5e93e6b4105e44.png","alt":"Added Key value map","title":"#display=block;margin=auto;width=600px;"},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add"]},". A new key value map is created and displays on the key value maps list."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select to open the newly created key value map, and select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["+"]}," to add a key value pair."," ",{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/content-assets/add-key-value-pair-b7d77a0d00163b90.png","alt":"Add Key value pair","title":"#display=block;margin=auto;width=600px;"},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["For the selected key value map, add these key value pairs:",{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["username"]},": Enter the email address you use for accessing Apigee Edge."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["password"]},": Enter a password for the pair."]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"task-2b-set-up-key-value-map-information-for-apigee-x","__idx":4},"children":["Task 2b): Set up key value map information for Apigee X"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["After uploading the proxy bundle, create key value maps and set up the service user credentials."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To create key value maps and set up user credentials:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["From Apigee X, navigate to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Admin > Environments > Key Value Maps"]},". The Key value maps page displays."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["+Key value map"]}," to display the ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Add key value map"]}," dialog."," ",{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/content-assets/add-key-value-map-x-fd6dbb41d6c68def.png","alt":"Add Key value map","title":"#display=block;margin=auto;width=600px;"},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Enter a name for the key value map."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add"]},". A new key value map is created and displays on the key value maps list."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Set the contents of the service account JSON file (see prerequisites) as the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["serviceAccountCredentialsFile"]}," parameter of the KVM."]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning","name":"Note"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You cannot add or retrieve data to the KVM in the Apigee X UI. You must use the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["KeyValueMapOperations"]}," policy to add or retrieve data to KVMs."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You can use ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://github.com/apigee/devrel/tree/main/references/kvm-admin-api"},"children":["https://github.com/apigee/devrel/tree/main/references/kvm-admin-api"]}," to set the values to the KVM. Follow these steps to set the value using Redocly's built-in policy."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["5.1. Navigate to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Develop > API Proxies"]}," and select to open the API proxy you created in Task 1."," ","5.2. Select ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Develop"]}," tab, and:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Under ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Policies"]},", select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["[example] Set Service Account Creds"]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Follow the instructions from the comment in the policy"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/content-assets/kvm-via-policy-b462d9e30040294c.png","alt":"Set Service Account creds via policy","title":"#display=block;margin=auto;width=600px;"},"children":[]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"task-3-map-authentication-credentials-and-deploy-proxy","__idx":5},"children":["Task 3: Map authentication credentials and deploy proxy"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Once you have set up the key value map information, you can map the authentication credentials and deploy the proxy to the appropriate environment."]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Navigate to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Develop > API Proxies"]}," and select to open the API proxy you created in Task 1."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Develop"]}," tab, and:",{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Under ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Policies"]},", select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Get Auth Creds"]}," for Apigee Edge or ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Get Service Account Creds"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Under ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Property Inspector"]},", for mapIdentifier, enter ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["system-user-creds"]}," (This is the key value map you created in Task 2)"," ",{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/content-assets/api-proxy-mapid-bf698af6b68eca3a.png","alt":"Map auth cred","title":"#display=block;margin=auto;width=600px;"},"children":[]}]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Save"]}," to save your changes."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["From the ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Deployment"]}," dropdown, select the environment you want to deploy the proxy to. A confirmation message displays."," ",{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/content-assets/api-proxy-deploy-053712bb8d7089f2.png","alt":"Deploy proxy","title":"#display=block;margin=auto;width=600px;"},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Deploy"]},". The proxy is now deployed to the selected environment and a deployment URL is generated for the proxy."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Overview"]}," tab to view the deployment URL."," ",{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/content-assets/api-deploy-url-6e2198fbabba0ee0.png","alt":"Deploy URL","title":"#display=block;margin=auto;width=600px;"},"children":[]}]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You need the deployment URL (proxy URL) for enabling your Redocly Portal ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs-legacy/developer-portal/guides/apigee-integration-portal/enable-ui-components"},"children":["Apigee UI components"]},"."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"task-4-configure-apigee-proxy-for-your-identity-provider","__idx":6},"children":["Task 4: Configure Apigee proxy for your identity provider"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In this step, organization owners add the JWKS URL from their OIDC provider into the Apigee proxy."]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In a browser, enter the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Config URL"]},". The browser displays a response in JSON format."," ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Tip"]},": You can find the Config URL in your OIDC setting."," ",{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/content-assets/oidc-config-url-cf2af8720d05ba92.png","alt":"OIDC connect","title":"#display=block;margin=auto;width=600px;"},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["From the response body, copy the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["jwks_URL"]}," value."," ",{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/content-assets/jwks-url-8639564bd7628dab.png","alt":"OIDC connect","title":"#display=block;margin=auto;width=600px;"},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Navigate to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Develop > API Proxies"]}," and select to open the API proxy you created in Task 1 and select the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Develop"]}," tab."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Under Policies, select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Verify JWT"]},". The Verify JWT code displays."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Paste the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["jwks_URL"]}," into the code for ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["JWKS uri"]},"."," ",{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/content-assets/verify-jwt-code-53d38a9bda832832.png","alt":"Verify JWT","title":"#display=block;margin=auto;width=600px;"},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Save"]}," to save your changes."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"next-steps","__idx":7},"children":["Next steps"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Continue to ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs-legacy/developer-portal/guides/apigee-integration-portal/enable-ui-components"},"children":["enable the UI components"]}," within your developer portal so that your portal users can ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs-legacy/developer-portal/guides/apigee-integration-portal/manage-apps-keys"},"children":["manage apps and keys"]},"."]}]},"frontmatter":{"seo":{"title":"Set up and configure the Apigee proxy for the Redocly Developer portal"},"excludeFromSearch":true},"tagList":["admonition"],"title":"Set up and configure the Apigee proxy for the Redocly Developer portal","lastModified":"2025-05-28T16:01:32.000Z"}