This documentation is for WSO2 API Manager 2.0.0. View documentation for the latest release.
Skip to end of metadata
Go to start of metadata

This section covers the following topics: 

Changing the super admin password

Follow the instructions below to change the default admin password:

  1. Sign in to the APIM management console with admin/admin credentials and use the Change my password option.
  2. After changing the credentials, change the same in the following files.

    • The <APIM_HOME>/repository/conf/user-mgt.xml file.


      Note that the password in the user-mgt.xml file is written to the primary user store when the server starts for the first time. Thereafter, the password will be validated from the primary user store and not from the user-mgt.xml file. Therefore, if you need to change the admin password stored in the user store, you cannot simply change the value in the user-mgt.xml file. To change the super admin password, you must use the Change Passwordoption from the management console.

    • The  <APIM_HOME>/repository/conf/ file.

      connectionfactory.TopicConnectionFactory = amqp://admin:[email protected]/carbon?brokerlist='tcp://localhost:5672'
      connectionfactory.QueueConnectionFactory = amqp://admin:[email protected]/test?brokerlist='tcp://localhost:5672'

Do you have any special characters in passwords?

  • If you specify passwords inside XML files, take care when giving special characters in the user names and passwords. According to XML specification (, some special characters can disrupt the configuration. For example, the ampersand character (&) must not appear in the literal form in XML files. It can cause a Java Null Pointer exception. You must wrap it with CDATA ( as shown below or remove the character:

        <![CDATA[[email protected]?qZ%Jv855&A4a,%M8B]]>
  • Note the following if you have special characters in the passwords on your file:

    • It is not possible to use the @ symbol in the username or password.
    • It is also not possible to use the percentage (%) sign in the password. When building the connection URL, the URL is parsed. This parsing exception happens because the percentage (%) sign acts as the escape character in URL parsing. If using the percentage (%) sign in the connection string is required, use the respective encoding character for the percentage (%) sign in the connection string. For example, if you need to pass adm%in as the password, then the % symbol should be encoded with its respective URL encoding character. Therefore, you have to send it as adm%25in.

      For a list of possible URL parsing patterns, see URL encoding reference.

Recovering a password

See How can I recover the admin password used to sign in to the management console?

Login in via multiple user store attributes

See Authentication using multiple attributes in the WSO2 IS documentation.

  • When setting up email login specify the complete username with tenant domain. If you are in super tenant mode username should be as follows. <username>@<email>@carbon.super
    Example :[email protected]@carbon.super.
  • When configuring <DataPublisher> section under <ThrottlingConfiguration> section in <PRODUCT_HOME>/repository/conf/api-manager.xml, specify the fully qualified username with tenant domain.
    Example : <Username>[email protected]</Username>
  • When specifing username in JMS Connection URL, under <JMSConnectionParameters> in <PRODUCT_HOME>/repository/conf/api-manager.xml, "@" characters should be replaced by "!" character.
    Example URL :

    <connectionfactory.TopicConnectionFactory><![CDATA[amqp://admin!!carbon.super:[email protected]/carbon?failover='roundrobin'&cyclecount='2'&brokerlist='tcp://'5'&connectdelay='50';tcp://'5'&connectdelay='50'']]></connectionfactory.TopicConnectionFactory>

Setting up primary and secondary logins

In a standalone deployment of the API Manager instance, users of the API Store can have a secondary login name in addition to the primary login name. This gives the user flexibility to provide either an email or a user name to sign in. You can configure the API Store to treat both login names as belonging to a single user. Users can invoke APIs with the same access token without having to create a new one for the secondary login. 

You can configure this capability using the steps below.

  1. Configure user login under the <OAuth> element in the <APIM_HOME>/repository/conf/api-manager.xml file.
    1. Set the primary attribute of the primary login to true and the primary attribute of the secondary login to false.
    2. Primary login doesn't have a ClaimUri. Leave this field empty.
    3. Provide the  correct  ClaimUri value for the secondary login.

    An example is given below:

        ..... . ....
            <UserIdLogin primary="true">
            <EmailLogin primary="false">
  2. In the API Store of a distributed setup, the serverURL element in the <APIM_HOME>/repository/conf/api-manager.xml file should point to the key manager instance's service endpoint. This allows users to connect to the key manager's user store to perform any operations related to the API Store such as login, access token generation etc. For example,

       <!--Server URL of the Authentication service -->
       <!-- Admin username for the Authentication manager. -->
       <!-- Admin password for the Authentication manager.-->

    If you have set the CheckPermissionRemotely parameter as true, the permissions will be checked in the remote server set in ServerURL. If the parameter is set as false the permissions will be checked by the local server

Tip: In a distributed setup, the API Store's user store needs to point to the key manager user store.

Tip: Be sure to keep the secondary login name unique to each user.

Setting up an e-mail login

See Email Authentication in the WSO2 IS documentation.

Setting up a social media login

You can auto-provision users based on a social network login by integrating the API Manager with WSO2 Identity Server. 

Note that auto-provisioning users based on social network login is not supported in a multi-tenant environment

In a multi-tenant environment, the system cannot identify the tenant domain in the login request that comes to the API Manager's Publisher/Store. Therefore, the service provider is registered as a SaaS application within the super tenant's space. Configuring user provisioning is part of creating the service provider. In order to authenticate the user through a third party identity provider such as a social network login, you must enable identity federation. As the service provider is created in the super tenant's space, the provisioned user is also created within the super tenant's space. As a result, it is not possible to provision the user in the tenant's space. 

To overcome this limitation, you can write a custom authenticator to retrieve the tenant domain of the user and write a custom login page where the user can enter the tenant domain, which is added to the authenticator context. Write a custom provisioning handler to provision the user in the tenant domain that is maintained in the context. 

  • No labels