Use Cases for Closing the IT–Business Gap — Featuring Nintex Customer, Optum
KB003484
When you register or refresh an instance of the REST Service type, you receive an error like Unhandled Exception while describing service (Inner: The remote server returned an error: (403) Forbidden). This error occurs when you use OAuth as the authentication mode for the Service Instance.
K2 uses the Authentication Mode specified for the Service Instance to retrieve the Swagger descriptor file at registration/refresh time, as well as at runtime to interact with the targeted system. If you use OAuth authentication, the Auth Headers for the specified OAuth resource are sent as auth headers to retrieve the descriptor file. If the descriptor file is located in a storage location that does not recognize the auth headers you will receive the 403 Forbidden error, because the system hosting the descriptor file does not accept the authentication headers used by the system that the REST service will connect to at runtime.
Suppose you created a Swagger descriptor file to interact with SalesForce APIs. You host the descriptor file as an anonymous file in Azure Blob Storage, and configure OAuth as the Authentication Mode for the Service Instance, using values for the SalesForce instance you will be connecting to at runtime. When you attempt to complete the service instance registration procedure, you receive the 403 Forbidden error. This is because Azure does not accept the OAuth authentication headers that are used to connect to SalesForce.
Two workarounds are currently known for this issue:
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
Sorry, we're still checking this file's contents to make sure it's safe to download. Please try again in a few minutes.
Sorry, our virus scanner detected that this file isn't safe to download.