Skip to content

updated Choreo terms with WSO2 Developer Platform term - #6268

Open
rusiru-erandaka wants to merge 2 commits into
wso2:masterfrom
rusiru-erandaka:Fixing_doc_issue_MFA_advanced_conditions_guide-_28184
Open

updated Choreo terms with WSO2 Developer Platform term#6268
rusiru-erandaka wants to merge 2 commits into
wso2:masterfrom
rusiru-erandaka:Fixing_doc_issue_MFA_advanced_conditions_guide-_28184

Conversation

@rusiru-erandaka

Copy link
Copy Markdown

##Changes

Updated all the "Choreo" terms with "WSO2 Developer Platform" term in https://wso2.com/identity-platform/docs/guides/authentication/conditional-auth/add-authentications-based-on-api-calls/ page.

@CLAassistant

CLAassistant commented Jul 17, 2026

Copy link
Copy Markdown

CLA assistant check
All committers have signed the CLA.

@coderabbitai

coderabbitai Bot commented Jul 17, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yml

Review profile: CHILL

Plan: Pro

Run ID: 8b45bfd5-83c3-47e5-b338-956ad0a406a8

📥 Commits

Reviewing files that changed from the base of the PR and between 431f02d and e8b6275.

📒 Files selected for processing (1)
  • en/includes/references/conditional-auth/api-reference.md
🚧 Files skipped from review as they are similar to previous changes (1)
  • en/includes/references/conditional-auth/api-reference.md

📝 Walkthrough

Walkthrough

Changes

The documentation replaces Choreo terminology with WSO2 Developer Platform references across conditional authentication, password migration, event monitoring, action guides, operational policies, release notes, and Branding AI instructions.

WSO2 Developer Platform documentation

Layer / File(s) Summary
Conditional API guidance
en/includes/guides/authentication/conditional-auth/add-authentications-based-on-api-calls.md, en/includes/references/conditional-auth/api-reference.md
Updates API setup, metadata, Secret mappings, logs, and reference examples to use WSO2 Developer Platform while retaining step-up MFA behavior.
Password migration platform guidance
en/includes/guides/authentication/conditional-auth/on-demand-silent-password-migration-template.md, en/includes/guides/fragments/migrate-users/configure-choreo-for-password-migration.md, en/includes/guides/users/migrate-users/migrate-passwords.md
Updates deployment instructions, endpoints, credentials, links, and runtime messages for WSO2 Developer Platform.
Event and platform references
en/asgardeo/docs/guides/monitoring/asgardeo-events.md, en/includes/guides/monitoring/index.md, en/asgardeo/docs/complete-guides/actions/*, en/asgardeo/docs/references/operational-policies.md, en/identity-server/7.0.0/docs/get-started/about-this-release.md
Replaces Choreo event-publishing, webhook, console, action, policy, and scheduled-integration references with WSO2 Developer Platform wording.
Branding AI console reference
en/asgardeo/docs/quick-starts/branding-ai.md
Updates the Branding AI instructions to use the console URL for branding extraction and application.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description is missing the required Purpose, Related PRs, Test environment, and Security checks sections from the template. Reformat the PR description to include all template sections, especially purpose, related PRs, tested environments, and security checkboxes.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main change: replacing Choreo terminology with WSO2 Developer Platform terminology.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In
`@en/includes/guides/authentication/conditional-auth/add-authentications-based-on-api-calls.md`:
- Around line 19-23: Update the Step 2 Markdown link target to
`#integrate-the-rest-api-with-wso2-developer-platform` so it matches the
generated anchor for the renamed integration heading. Leave the link text and
other anchors unchanged.
- Line 227: Update the description of connectionMetadata to qualify each field’s
source, explicitly identifying asgardeoTokenEndpoint as coming from WSO2
Identity Platform and the remaining values as coming from WSO2 Developer
Platform, or mention both platforms together.
- Around line 139-141: Update the sample at
en/includes/guides/authentication/conditional-auth/add-authentications-based-on-api-calls.md:139-141
to identify the consumer key and secret as application credentials issued to the
application created on WSO2 Developer Platform. Apply the same
application-credential wording to the parameter descriptions at :182-190 and
stored Secret note at :199-208, and correct the field casing from consumerkey to
consumerKey at :199-208.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yml

Review profile: CHILL

Plan: Pro

Run ID: 02e1bab2-696e-4709-bf6f-40eaf48e9eeb

📥 Commits

Reviewing files that changed from the base of the PR and between 9f35244 and c4d736f.

📒 Files selected for processing (1)
  • en/includes/guides/authentication/conditional-auth/add-authentications-based-on-api-calls.md

Comment on lines +139 to +141
"url": "<Developer Platform API URL>",
"consumerKey": "<Consumer key of the WSO2 Developer Platform>",
"consumerSecret": "<Consumer secret of the WSO2 Developer Platform>",

@coderabbitai coderabbitai Bot Jul 17, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Describe the consumer credentials as application credentials.

The consumer key and secret are issued to the application created on WSO2 Developer Platform, not to WSO2 Developer Platform itself. Use that wording consistently in the sample, parameter table, and stored Secret note. Also correct the identifier casing from consumerkey to consumerKey.

  • en/includes/guides/authentication/conditional-auth/add-authentications-based-on-api-calls.md#L139-L141: identify the application as the credential owner.
  • en/includes/guides/authentication/conditional-auth/add-authentications-based-on-api-calls.md#L182-L190: correct the parameter descriptions.
  • en/includes/guides/authentication/conditional-auth/add-authentications-based-on-api-calls.md#L199-L208: correct the stored Secret wording and field casing.
📍 Affects 1 file
  • en/includes/guides/authentication/conditional-auth/add-authentications-based-on-api-calls.md#L139-L141 (this comment)
  • en/includes/guides/authentication/conditional-auth/add-authentications-based-on-api-calls.md#L182-L190
  • en/includes/guides/authentication/conditional-auth/add-authentications-based-on-api-calls.md#L199-L208
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@en/includes/guides/authentication/conditional-auth/add-authentications-based-on-api-calls.md`
around lines 139 - 141, Update the sample at
en/includes/guides/authentication/conditional-auth/add-authentications-based-on-api-calls.md:139-141
to identify the consumer key and secret as application credentials issued to the
application created on WSO2 Developer Platform. Apply the same
application-credential wording to the parameter descriptions at :182-190 and
stored Secret note at :199-208, and correct the field casing from consumerkey to
consumerKey at :199-208.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is not properly resolved. could u please check again?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@pavinduLakshan, you are right. I rechecked the current content, and the comment is not resolved.

The guide still describes the credentials as belonging to “WSO2 Developer Platform,” although the preceding step creates an application and obtains that application's credentials. It also still uses the incorrect consumerkey casing in the stored Secret note.

Please update the wording consistently, for example:

"consumerKey": "<Consumer key of the application created on WSO2 Developer Platform>",
"consumerSecret": "<Consumer secret of the application created on WSO2 Developer Platform>",

Also update the parameter table and stored Secret text to refer to the application’s consumer key and consumer secret, and change consumerkey to consumerKey.

I also noticed a separate inconsistency in the sample: Line 151 logs “Calling the API hosted in WSO2 Identity Platform!”, but the API is hosted on WSO2 Developer Platform. 🐇


??? note "Use a stored `Secret`"
If you don't want to enter the `consumerkey` and `consumerSecret` obtained from the Choreo application every time you use the conditional authentication script, you can store them as **Secret**s on WSO2 Identity Platform.
If you don't want to enter the `consumerkey` and `consumerSecret` obtained from the WSO2 Developer Platform every time you use the conditional authentication script, you can store them as **Secret**s on WSO2 Identity Platform.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

the "application" term seem to have been missed during the renaming in several places. Please check and update those places including this one.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

sure

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 7

Note

Due to the large number of review comments, Critical, Major severity comments were prioritized as inline comments.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
en/asgardeo/docs/guides/monitoring/asgardeo-events.md (1)

127-141: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Replace the deprecated webhook docs link The linked WSO2 Developer Platform page is deprecated, and these steps no longer match the active workflow. Update the links to the current webhook guide and align the creation and deployment steps with it.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@en/asgardeo/docs/guides/monitoring/asgardeo-events.md` around lines 127 -
141, Update the webhook setup section around the “Select a Type” step to use the
current, non-deprecated webhook guide links. Revise the creation and deployment
instructions to match the active workflow described by that guide, including any
changed UI labels, authorization, buildpack, repository, access-mode, and
deployment steps.
🟡 Minor comments (17)
en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/index.md-5-13 (1)

5-13: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Use a colon before the list.

“Protect your application by,” is grammatically incorrect. Change the comma to a colon.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/index.md`
around lines 5 - 13, Update the introductory phrase in the Identity Gateway
tutorial from “by,” to “by:” immediately before the list, leaving the list items
unchanged.

Source: Coding guidelines

en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-oauth2proxy.md-94-97 (1)

94-97: 🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win

Mark the insecure cookie setting as development-only.

The main configuration sets cookie_secure = false, so cookies can be sent over unencrypted HTTP. Add an explicit local-development warning and require cookie_secure = true whenever the proxy is deployed over HTTPS.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-oauth2proxy.md`
around lines 94 - 97, Update the OAuth2 Proxy configuration example around
cookie_secure to explicitly mark false as local-development-only, and instruct
users to set cookie_secure = true for HTTPS deployments. Preserve the
surrounding cookie settings and secret placeholder.
en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-oathkeeper.md-169-171 (1)

169-171: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Fix the Oathkeeper spelling.

Change Oathkeepr to Oathkeeper.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-oathkeeper.md`
around lines 169 - 171, Correct the misspelled “Oathkeepr” reference in the
“Learn more” note to “Oathkeeper,” including the linked documentation text while
leaving the URL and surrounding content unchanged.

Source: Coding guidelines

en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-mod-auth-openidc.md-65-73 (1)

65-73: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Use --with-apxs in the troubleshooting command. mod_auth_openidc accepts --with-apxs=PATH; --with-apxs2 is not a supported configure option and will fail before the build starts. en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-mod-auth-openidc.md:80-83

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-mod-auth-openidc.md`
around lines 65 - 73, Update the mod_auth_openidc troubleshooting command to use
the supported --with-apxs=PATH configure option instead of --with-apxs2,
matching the build command’s configure syntax and ensuring the command succeeds.
en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-oauth2proxy.md-88-90 (1)

88-90: 🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win

Do not forward the access token in the sample config.

pass_access_token = true and set_authorization_header = true send the bearer token to the upstream application even though this tutorial only needs identity headers. Keep these settings out of the baseline example and add them only for applications that explicitly require the token.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-oauth2proxy.md`
around lines 88 - 90, Remove pass_access_token and set_authorization_header from
the baseline OAuth2 Proxy sample configuration, while retaining
pass_user_headers = true for identity headers. Do not add token forwarding
elsewhere in the example; applications requiring the bearer token can configure
those options separately.
en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-mod-auth-openidc.md-165-182 (1)

165-182: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Document OIDC_id_token only with the matching directive. OIDC_CLAIM_sub and OIDC_access_token follow the default mod_auth_openidc behavior, but OIDC_id_token is exposed only when OIDCPassIDTokenAs is set to serialized. Add that directive here or remove the header from the list.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-mod-auth-openidc.md`
around lines 165 - 182, Update the header list and accompanying httpd-oidc.conf
example so OIDC_id_token is documented only when OIDCPassIDTokenAs is configured
as serialized; otherwise remove OIDC_id_token from the documented headers. Keep
the existing OIDC_CLAIM_sub and OIDC_access_token entries unchanged.
en/asgardeo/docs/guides/authentication/conditional-auth/acr-based-adaptive-auth.md-152-152 (1)

152-152: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Correct the spelling error.

Change authentiaction to authentication.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@en/asgardeo/docs/guides/authentication/conditional-auth/acr-based-adaptive-auth.md`
at line 152, Correct the spelling of “authentiaction” to “authentication” in the
affected documentation sentence, without changing the surrounding text.
en/asgardeo/docs/guides/authentication/conditional-auth/acr-based-adaptive-auth.md-28-29 (1)

28-29: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Correct the spelling error.

Change Eventhough to Even though.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@en/asgardeo/docs/guides/authentication/conditional-auth/acr-based-adaptive-auth.md`
around lines 28 - 29, In the “Some commonly accepted ACR values” details
section, correct the spelling by changing “Eventhough” to “Even though” while
leaving the rest of the sentence unchanged.
en/asgardeo/docs/guides/authentication/conditional-auth/acr-based-adaptive-auth.md-13-15 (1)

13-15: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Fix grammar in the scenario bullets.

Use “high-value transaction,” remove “request for,” and change “which generally include” to “which generally includes.”

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@en/asgardeo/docs/guides/authentication/conditional-auth/acr-based-adaptive-auth.md`
around lines 13 - 15, Fix the grammar in the two scenario bullets: change “high
value transaction” to “high-value transaction,” remove “for” after “request,”
and change “which generally include” to “which generally includes.”

Sources: Coding guidelines, Linters/SAST tools

en/asgardeo/docs/guides/authentication/conditional-auth/acr-based-adaptive-auth.md-113-113 (1)

113-113: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Fix the skipped procedure number.

The procedure jumps from step 4 to step 6. Change Line 113 to step 5.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@en/asgardeo/docs/guides/authentication/conditional-auth/acr-based-adaptive-auth.md`
at line 113, Correct the procedure numbering in the ACR-based adaptive
authentication guide by changing the visible “6. Click Update to confirm.” step
to step 5, preserving the existing instruction text.
en/includes/guides/authentication/conditional-auth/on-demand-silent-password-migration-template.md-698-698 (1)

698-698: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Fix the subject-verb agreement.

Change “The connectionMetadata object hold” to “The connectionMetadata object holds.”

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@en/includes/guides/authentication/conditional-auth/on-demand-silent-password-migration-template.md`
at line 698, In the sentence describing the connectionMetadata object, update
the verb to “holds” so it agrees with the singular subject “object.”
en/includes/references/conditional-auth/api-reference.md-736-736 (1)

736-736: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Remove the extra C from the URL placeholder.

Use <WSO2 Developer Platform API URL> instead of <CWSO2 Developer Platform API URL>.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@en/includes/references/conditional-auth/api-reference.md` at line 736, Update
the URL placeholder in the API reference example by removing the leading extra
“C”, changing it to <WSO2 Developer Platform API URL> while preserving the
surrounding JSON structure.
en/includes/guides/fragments/migrate-users/configure-choreo-for-password-migration.md-43-43 (1)

43-43: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Use sign in for user-facing actions.

Replace login and log in in these instructions with sign in to follow the current documentation terminology guideline consistently.

Also applies to: 51-51, 99-99

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@en/includes/guides/fragments/migrate-users/configure-choreo-for-password-migration.md`
at line 43, Update the user-facing instructions in the migration guide to
replace “login” and “log in” with “sign in,” including the referenced
occurrences at lines 51 and 99. Preserve the existing links and instructional
meaning.

Source: Coding guidelines

en/includes/guides/monitoring/index.md-8-8 (1)

8-8: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Remove the duplicated platform name.

Change “WSO2's WSO2 Developer Platform platform” to “the WSO2 Developer Platform”.

As per coding guidelines, use official product names exactly and use one term per concept.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@en/includes/guides/monitoring/index.md` at line 8, Update the event
publication sentence in the monitoring guide to replace “WSO2's WSO2 Developer
Platform platform” with the official product name “the WSO2 Developer Platform,”
preserving the surrounding links and wording.

Source: Coding guidelines

en/asgardeo/docs/guides/monitoring/asgardeo-events.md-144-144 (1)

144-144: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Use active voice in the callback URL note.

Rewrite this as: “If the callback URL does not populate, manually copy the invoke URL and paste it into the designated field.”

As per coding guidelines, Markdown documentation should use active voice and precise, direct wording.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@en/asgardeo/docs/guides/monitoring/asgardeo-events.md` at line 144, Rewrite
the callback URL note near the monitoring instructions in active voice and
direct wording: state that if the callback URL does not populate, the user
should manually copy the invoke URL and paste it into the designated field.
Remove the passive phrasing and the unnecessary continuity explanation.

Sources: Coding guidelines, Linters/SAST tools

en/asgardeo/docs/quick-starts/branding-ai.md-87-93 (1)

87-93: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Use descriptive link text for the console references.

Replace the raw URL link text with a label such as [WSO2 Developer Platform Console].

As per coding guidelines, use descriptive link text instead of pasting raw URLs.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@en/asgardeo/docs/quick-starts/branding-ai.md` around lines 87 - 93, Replace
the raw console URL text in both links within the Branding AI documentation with
descriptive link text such as “WSO2 Developer Platform Console,” while
preserving the existing destination URL and target behavior.

Source: Coding guidelines

en/asgardeo/docs/quick-starts/branding-ai.md-89-89 (1)

89-89: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Fix the duplicated verb.

Change “Make sure to click Save and Publish save the generated branding design” to “Make sure to click Save and Publish to save the generated branding design.”

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@en/asgardeo/docs/quick-starts/branding-ai.md` at line 89, Correct the
sentence in the branding quick-start instructions by adding “to” after the
**Save and Publish** action, so it reads “Make sure to click **Save and
Publish** to save the generated branding design and apply it.”
🧹 Nitpick comments (1)
en/asgardeo/docs/guides/authentication/conditional-auth/acr-based-adaptive-auth.md (1)

5-5: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Use the repository’s standard acronym form.

Use OIDC without expanding it to “OpenID Connect” on first use, consistent with the repository’s IAM documentation convention.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@en/asgardeo/docs/guides/authentication/conditional-auth/acr-based-adaptive-auth.md`
at line 5, Update the ACR description to use the repository-standard acronym
form by replacing the first-use expansion “OpenID Connect (OIDC)” with “OIDC” in
the authentication context explanation. Keep the surrounding SAML and adaptive
authentication guidance unchanged.

Source: Learnings

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@en/asgardeo/docs/guides/authentication/conditional-auth/acr-and-amr.md`:
- Line 5: The introductory description should distinguish ACR from AMR by
protocol and token contract. Update the opening text to identify amr as an OIDC
ID token claim and ACR as the assurance-context value used in OIDC and
represented in SAML by AuthnContextClassRef, rather than presenting both as
equivalent parameters across both protocols.

In
`@en/asgardeo/docs/guides/authentication/conditional-auth/acr-based-adaptive-auth.md`:
- Line 45: Update the ACR value documentation in the affected sections to
consistently describe OIDC ACR values as space-separated, matching the request
examples. Clarify that supportedAcrValues is an array of supported values, and
revise the JavaScript example and all referenced occurrences accordingly without
changing the authentication behavior.

In `@en/asgardeo/docs/guides/monitoring/asgardeo-events.md`:
- Around line 117-120: The organization creation instruction conflicts with the
synchronization note by requiring a matching email address without documenting
that constraint. Update the prerequisite step to require only the same
organization name, preserving consistency with the stated name-based
synchronization rule.

In
`@en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-mod-auth-openidc.md`:
- Around line 108-119: Update the Apache configuration example around
OIDCCryptoPassphrase to clearly mark a-random-secret-value as a placeholder, and
add guidance to replace it with a long, randomly generated passphrase. Keep the
existing client credential placeholder instructions unchanged.
- Around line 21-24: Make the authorized redirect URL in the “Register a
Traditional Web Application” instructions use the exact callback path configured
by Apache’s OIDCRedirectURI, updating the example and related wording so both
registration and configuration consistently reference the same URI.

In
`@en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-oathkeeper.md`:
- Around line 123-127: Update the Oathkeeper endpoint in the TLS sample
configuration to use https://localhost:9444, while retaining
http://localhost:4455 exclusively in the no-TLS instructions. Leave the other
service endpoints unchanged.
- Around line 223-230: Update the Oathkeeper YAML listener configuration by
nesting the port under serve.proxy.port and removing the tls.cert and tls.key
entries. Keep the example aligned with Oathkeeper v0.40.9, with TLS termination
handled by the fronting proxy.

---

Outside diff comments:
In `@en/asgardeo/docs/guides/monitoring/asgardeo-events.md`:
- Around line 127-141: Update the webhook setup section around the “Select a
Type” step to use the current, non-deprecated webhook guide links. Revise the
creation and deployment instructions to match the active workflow described by
that guide, including any changed UI labels, authorization, buildpack,
repository, access-mode, and deployment steps.

---

Minor comments:
In
`@en/asgardeo/docs/guides/authentication/conditional-auth/acr-based-adaptive-auth.md`:
- Line 152: Correct the spelling of “authentiaction” to “authentication” in the
affected documentation sentence, without changing the surrounding text.
- Around line 28-29: In the “Some commonly accepted ACR values” details section,
correct the spelling by changing “Eventhough” to “Even though” while leaving the
rest of the sentence unchanged.
- Around line 13-15: Fix the grammar in the two scenario bullets: change “high
value transaction” to “high-value transaction,” remove “for” after “request,”
and change “which generally include” to “which generally includes.”
- Line 113: Correct the procedure numbering in the ACR-based adaptive
authentication guide by changing the visible “6. Click Update to confirm.” step
to step 5, preserving the existing instruction text.

In `@en/asgardeo/docs/guides/monitoring/asgardeo-events.md`:
- Line 144: Rewrite the callback URL note near the monitoring instructions in
active voice and direct wording: state that if the callback URL does not
populate, the user should manually copy the invoke URL and paste it into the
designated field. Remove the passive phrasing and the unnecessary continuity
explanation.

In `@en/asgardeo/docs/quick-starts/branding-ai.md`:
- Around line 87-93: Replace the raw console URL text in both links within the
Branding AI documentation with descriptive link text such as “WSO2 Developer
Platform Console,” while preserving the existing destination URL and target
behavior.
- Line 89: Correct the sentence in the branding quick-start instructions by
adding “to” after the **Save and Publish** action, so it reads “Make sure to
click **Save and Publish** to save the generated branding design and apply it.”

In
`@en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/index.md`:
- Around line 5-13: Update the introductory phrase in the Identity Gateway
tutorial from “by,” to “by:” immediately before the list, leaving the list items
unchanged.

In
`@en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-mod-auth-openidc.md`:
- Around line 65-73: Update the mod_auth_openidc troubleshooting command to use
the supported --with-apxs=PATH configure option instead of --with-apxs2,
matching the build command’s configure syntax and ensuring the command succeeds.
- Around line 165-182: Update the header list and accompanying httpd-oidc.conf
example so OIDC_id_token is documented only when OIDCPassIDTokenAs is configured
as serialized; otherwise remove OIDC_id_token from the documented headers. Keep
the existing OIDC_CLAIM_sub and OIDC_access_token entries unchanged.

In
`@en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-oathkeeper.md`:
- Around line 169-171: Correct the misspelled “Oathkeepr” reference in the
“Learn more” note to “Oathkeeper,” including the linked documentation text while
leaving the URL and surrounding content unchanged.

In
`@en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-oauth2proxy.md`:
- Around line 94-97: Update the OAuth2 Proxy configuration example around
cookie_secure to explicitly mark false as local-development-only, and instruct
users to set cookie_secure = true for HTTPS deployments. Preserve the
surrounding cookie settings and secret placeholder.
- Around line 88-90: Remove pass_access_token and set_authorization_header from
the baseline OAuth2 Proxy sample configuration, while retaining
pass_user_headers = true for identity headers. Do not add token forwarding
elsewhere in the example; applications requiring the bearer token can configure
those options separately.

In
`@en/includes/guides/authentication/conditional-auth/on-demand-silent-password-migration-template.md`:
- Line 698: In the sentence describing the connectionMetadata object, update the
verb to “holds” so it agrees with the singular subject “object.”

In
`@en/includes/guides/fragments/migrate-users/configure-choreo-for-password-migration.md`:
- Line 43: Update the user-facing instructions in the migration guide to replace
“login” and “log in” with “sign in,” including the referenced occurrences at
lines 51 and 99. Preserve the existing links and instructional meaning.

In `@en/includes/guides/monitoring/index.md`:
- Line 8: Update the event publication sentence in the monitoring guide to
replace “WSO2's WSO2 Developer Platform platform” with the official product name
“the WSO2 Developer Platform,” preserving the surrounding links and wording.

In `@en/includes/references/conditional-auth/api-reference.md`:
- Line 736: Update the URL placeholder in the API reference example by removing
the leading extra “C”, changing it to <WSO2 Developer Platform API URL> while
preserving the surrounding JSON structure.

---

Nitpick comments:
In
`@en/asgardeo/docs/guides/authentication/conditional-auth/acr-based-adaptive-auth.md`:
- Line 5: Update the ACR description to use the repository-standard acronym form
by replacing the first-use expansion “OpenID Connect (OIDC)” with “OIDC” in the
authentication context explanation. Keep the surrounding SAML and adaptive
authentication guidance unchanged.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yml

Review profile: CHILL

Plan: Pro

Run ID: 0f4f3bfe-297b-43d7-a45f-2c1eb5caaba8

📥 Commits

Reviewing files that changed from the base of the PR and between ae2658e and 759978c.

⛔ Files ignored due to path filters (9)
  • en/asgardeo/docs/assets/img/guides/conditional-auth/acr-based-adaptive-auth-with-visual-editor.png is excluded by !**/*.png
  • en/asgardeo/docs/assets/img/tutorials/protect-apps-with-identity-gateway/identity_gateway_architecture.png is excluded by !**/*.png
  • en/asgardeo/docs/assets/img/tutorials/protect-apps-with-identity-gateway/mod_auth_openidc_architecture.png is excluded by !**/*.png
  • en/asgardeo/docs/assets/img/tutorials/protect-apps-with-identity-gateway/mod_auth_openidc_logged_in.png is excluded by !**/*.png
  • en/asgardeo/docs/assets/img/tutorials/protect-apps-with-identity-gateway/oathkeeper-architecture.png is excluded by !**/*.png
  • en/asgardeo/docs/assets/img/tutorials/protect-apps-with-identity-gateway/oathkeeper-logged-in.png is excluded by !**/*.png
  • en/asgardeo/docs/assets/img/tutorials/protect-apps-with-identity-gateway/oauth2proxy-architecture.png is excluded by !**/*.png
  • en/asgardeo/docs/assets/img/tutorials/protect-apps-with-identity-gateway/oauth2proxy-logged-in.png is excluded by !**/*.png
  • en/asgardeo/docs/assets/img/tutorials/protect-apps-with-identity-gateway/sample-app-running.png is excluded by !**/*.png
📒 Files selected for processing (24)
  • en/asgardeo/docs/apis/restapis/discoverable-application.yaml
  • en/asgardeo/docs/apis/user-discoverable-applications.md
  • en/asgardeo/docs/complete-guides/actions/pre-issue-access-token-action-in-choreo.md
  • en/asgardeo/docs/complete-guides/actions/pre-update-password-action-in-choreo.md
  • en/asgardeo/docs/complete-guides/actions/pre-update-profile-action-in-choreo.md
  • en/asgardeo/docs/guides/authentication/conditional-auth/acr-and-amr.md
  • en/asgardeo/docs/guides/authentication/conditional-auth/acr-based-adaptive-auth.md
  • en/asgardeo/docs/guides/monitoring/asgardeo-events.md
  • en/asgardeo/docs/quick-starts/branding-ai.md
  • en/asgardeo/docs/references/data-residency-in-asgardeo.md
  • en/asgardeo/docs/references/operational-policies.md
  • en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/index.md
  • en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-mod-auth-openidc.md
  • en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-oathkeeper.md
  • en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-oauth2proxy.md
  • en/asgardeo/mkdocs.yml
  • en/identity-server/7.0.0/docs/get-started/about-this-release.md
  • en/includes/guides/account-configurations/user-onboarding/self-registration.md
  • en/includes/guides/authentication/conditional-auth/add-authentications-based-on-api-calls.md
  • en/includes/guides/authentication/conditional-auth/on-demand-silent-password-migration-template.md
  • en/includes/guides/fragments/migrate-users/configure-choreo-for-password-migration.md
  • en/includes/guides/monitoring/index.md
  • en/includes/guides/users/migrate-users/migrate-passwords.md
  • en/includes/references/conditional-auth/api-reference.md
🚧 Files skipped from review as they are similar to previous changes (1)
  • en/includes/guides/authentication/conditional-auth/add-authentications-based-on-api-calls.md


### From an OIDC application

`acr_values` is an optional parameter that can be included in an OIDC authentication request. This parameter may include the necessary context class URIs. If there are multiple ACR values they can be included separated by commas.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Use one consistent representation for ACR values.

Line 45 says OIDC ACR values are comma-separated, while the request examples use spaces. The JavaScript example uses an array, not a comma-separated string. Document OIDC values as space-separated and describe supportedAcrValues as an array of supported values.

Also applies to: 54-54, 64-64, 120-124, 169-169

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@en/asgardeo/docs/guides/authentication/conditional-auth/acr-based-adaptive-auth.md`
at line 45, Update the ACR value documentation in the affected sections to
consistently describe OIDC ACR values as space-separated, matching the request
examples. Clarify that supportedAcrValues is an array of supported values, and
revise the JavaScript example and all referenced occurrences accordingly without
changing the authentication behavior.

Comment on lines +117 to +120
1. Navigate to [WSO2 Developer Platform](https://console.choreo.dev/login){:target="_blank"} and if you don't have one already, create an organization with the same name and email address you used to create your WSO2 Identity Platform organization.

!!! info
Organizations in WSO2 Identity Platform and Choreo synchronize based on their names.
Organizations in WSO2 Identity Platform and WSO2 Developer Platform synchronize based on their names.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Align the organization prerequisite with the synchronization rule.

The step requires the same organization name and email address, but the following note says organizations synchronize based on their names. Remove the email requirement or document the additional email constraint explicitly.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@en/asgardeo/docs/guides/monitoring/asgardeo-events.md` around lines 117 -
120, The organization creation instruction conflicts with the synchronization
note by requiring a matching email address without documenting that constraint.
Update the prerequisite step to require only the same organization name,
preserving consistency with the stated name-based synchronization rule.

Comment on lines +21 to +24
2. [Register a Traditional Web Application]({{base_path}}/guides/applications/register-oidc-web-app/) with the **OpenID Connect** protocol and the following details:

- **Name** - mod-auth-app
- **Authorized redirect URL** - The URL where {{product_name}} sends the authentication response after login. For example: `http://localhost:8002/oauth2/callback` (or your proxy callback URL).

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

file='en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-mod-auth-openidc.md'

echo '=== file stats ==='
wc -l "$file"

echo '=== lines 1-260 with numbers ==='
sed -n '1,260p' "$file" | nl -ba | sed -n '1,260p'

echo '=== searches ==='
rg -n --no-heading 'OIDCRedirectURI|with-apxs|with-apxs2|OIDCClaimPrefix|passphrase|claim headers|header' "$file"

Repository: wso2/docs-is

Length of output: 358


🏁 Script executed:

#!/bin/bash
set -euo pipefail
pwd
git ls-files 'en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-mod-auth-openidc.md'
sed -n '1,240p' 'en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-mod-auth-openidc.md' | nl -ba | sed -n '1,240p'

Repository: wso2/docs-is

Length of output: 320


🏁 Script executed:

#!/bin/bash
set -euo pipefail

file='en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-mod-auth-openidc.md'

echo '=== key ranges with line numbers ==='
awk 'NR>=1 && NR<=240 {printf "%4d  %s\n", NR, $0}' "$file" | sed -n '1,240p'

echo '=== term search with line numbers ==='
grep -nE 'OIDCRedirectURI|with-apxs|with-apxs2|OIDCClaimPrefix|passphrase|claim headers|header' "$file" || true

Repository: wso2/docs-is

Length of output: 12114


🏁 Script executed:

#!/bin/bash
set -euo pipefail

file='en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-mod-auth-openidc.md'

echo '=== lines 15-35 ==='
awk 'NR>=15 && NR<=35 {printf "%4d  %s\n", NR, $0}' "$file"

echo '=== lines 60-90 ==='
awk 'NR>=60 && NR<=90 {printf "%4d  %s\n", NR, $0}' "$file"

echo '=== lines 100-130 ==='
awk 'NR>=100 && NR<=130 {printf "%4d  %s\n", NR, $0}' "$file"

echo '=== lines 160-190 ==='
awk 'NR>=160 && NR<=190 {printf "%4d  %s\n", NR, $0}' "$file"

echo '=== matches ==='
grep -nE 'OIDCRedirectURI|with-apxs|with-apxs2|OIDCClaimPrefix|passphrase|claim headers|header' "$file" || true

Repository: wso2/docs-is

Length of output: 6400


Make the redirect URI path consistent.
http://localhost:8002/oauth2/callback in the application registration must match OIDCRedirectURI in the Apache config exactly; use the same callback path in both places.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-mod-auth-openidc.md`
around lines 21 - 24, Make the authorized redirect URL in the “Register a
Traditional Web Application” instructions use the exact callback path configured
by Apache’s OIDCRedirectURI, updating the example and related wording so both
registration and configuration consistently reference the same URI.

Comment on lines +108 to +119
```apache
Listen 8002
<VirtualHost *:8002>
ServerName localhost

OIDCCryptoPassphrase a-random-secret-value

OIDCProviderMetadataURL https://api.asgardeo.io/t/<organization_name>/oauth2/token/.well-known/openid-configuration

OIDCClientID YOUR_CLIENT_ID
OIDCClientSecret YOUR_CLIENT_SECRET
OIDCRedirectURI http://localhost:8002/callback

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

file='en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-mod-auth-openidc.md'

# Show the target section with line numbers.
sed -n '90,140p' "$file" | cat -n

# Search for the crypto passphrase and placeholder language elsewhere in the doc.
rg -n "OIDCCryptoPassphrase|random-secret|placeholder|replace" "$file"

Repository: wso2/docs-is

Length of output: 2515


Require a generated crypto passphrase. OIDCCryptoPassphrase a-random-secret-value looks like executable configuration, but the note only tells readers to replace the client credentials. Mark this value as a placeholder and instruct readers to use a long, randomly generated passphrase.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-mod-auth-openidc.md`
around lines 108 - 119, Update the Apache configuration example around
OIDCCryptoPassphrase to clearly mark a-random-secret-value as a placeholder, and
add guidance to replace it with a long, randomly generated passphrase. Keep the
existing client credential placeholder instructions unchanged.

Comment on lines +123 to +127
- This sample configuration file assumes that the following services run on the specified endpoints. If your setup differs, adjust the configuration accordingly.

- {{product_name}}: `https://api.asgardeo.io/t/<organization_name>`
- Oathkeeper: `http://localhost:9444`
- Back-end Service (API or Web Application): `http://localhost:8080`

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Use HTTPS for the TLS sample endpoint. The sample lists http://localhost:9444, but the TLS path should use https://localhost:9444. Keep http://localhost:4455 only in the no-TLS instructions.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-oathkeeper.md`
around lines 123 - 127, Update the Oathkeeper endpoint in the TLS sample
configuration to use https://localhost:9444, while retaining
http://localhost:4455 exclusively in the no-TLS instructions. Leave the other
service endpoints unchanged.

Comment on lines +223 to +230
```yaml
port: 9444
tls:
cert:
path: "/path/to/cert.pem"
key:
path: "/path/to/cert.key"
```

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

file='en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-oathkeeper.md'

# Show the relevant section with line numbers.
sed -n '200,250p' "$file" | cat -n

# Find nearby mentions of proxy.port / port to compare the examples.
rg -n --context 2 'proxy\.port|^\s*port:' "$file"

Repository: wso2/docs-is

Length of output: 2005


🌐 Web query:

Oathkeeper v0.40.9 configuration port tls cert key top-level port proxy.port schema

💡 Result:

In Ory Oathkeeper v0.40.9, the configuration for network services, including ports and TLS settings, is handled under the top-level serve key in the configuration file (typically config.yaml) [1][2]. The configuration schema separates the proxy (the main IAP proxy) and the API (for management/configuration) [1][2]. Below is the structure for configuring ports and TLS: serve: proxy: port: 4455 # Default port for the proxy [3][2] host: 127.0.0.1 # Optional host binding [1][2] tls: key: path: /path/to/key.pem # Path to the TLS private key [1] cert: path: /path/to/cert.pem # Path to the TLS certificate [1] api: port: 4456 # Default port for the administrative API [4][2] host: 127.0.0.1 tls: key: path: /path/to/key.pem cert: path: /path/to/cert.pem Key Configuration Details: - Port Configuration: Managed via serve.proxy.port and serve.api.port [1][2]. - TLS Configuration: Managed within each respective service block (serve.proxy.tls or serve.api.tls) [1]. The TLS structure requires defining a key and cert object, each containing a path field (pointing to the file on disk) or a base64 field (for inline encoded data) [5][1]. - Format: Configuration can be provided as a YAML, JSON, or TOML file [6], or via environment variables [6][4]. For production deployments, specifically in Kubernetes, these ports are often managed by Helm values (e.g., service.proxy.port: 4455) [3][7], which align with the application's internal serve configuration [8].

Citations:


🌐 Web query:

site:ory.com Oathkeeper configuration serve proxy port tls cert key v0.40.9

💡 Result:

In Ory Oathkeeper, the serve command exposes two separate ports: one for the reverse proxy and one for the API (which includes the Access Control Decision API) [1][2]. These are configured via the serve block in your configuration file (YAML, JSON, or TOML) [1][3][2]. Example configuration for setting ports: serve: proxy: port: 4455 api: port: 4456 Regarding TLS, Ory Oathkeeper is designed to be deployed behind a dedicated TLS-terminating reverse proxy or API gateway (such as Nginx, Envoy, or AWS API Gateway) [2][4]. The Oathkeeper binary itself does not natively handle TLS termination for incoming requests to the proxy or API ports [1][2]. Consequently, there are no configuration keys such as tls.cert or tls.key for the serve proxy or API ports in the Oathkeeper configuration. If your architecture requires TLS, you should terminate the TLS connection at the ingress/load balancer level and forward the traffic to Oathkeeper over plain HTTP [2][4].

Citations:


Move the listener config under serve.proxy, and drop the TLS keys. Oathkeeper v0.40.9 expects the proxy port at serve.proxy.port, and TLS termination belongs in a fronting proxy rather than tls.cert/tls.key in this file. As written, this block points readers at unsupported keys and will not work as shown.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@en/asgardeo/docs/references/tutorials/protect-apps-with-identity-gateway/protect-apps-with-oathkeeper.md`
around lines 223 - 230, Update the Oathkeeper YAML listener configuration by
nesting the port under serve.proxy.port and removing the tls.cert and tls.key
entries. Keep the example aligned with Oathkeeper v0.40.9, with TLS termination
handled by the fronting proxy.

@pavinduLakshan

Copy link
Copy Markdown
Member

It seems that 8 other already merged commits are also in your pr. Shall we try updating your branch with master to only include commits from you?

@rusiru-erandaka
rusiru-erandaka force-pushed the Fixing_doc_issue_MFA_advanced_conditions_guide-_28184 branch from 759978c to 431f02d Compare July 20, 2026 05:16

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@en/includes/guides/users/migrate-users/migrate-passwords.md`:
- Line 131: Align the link in the migrate-passwords guide with the renamed
platform: either update the linked tutorial path and its content so it describes
WSO2 Developer Platform, or revert the link text to the existing Choreo
terminology until that migration is complete. Keep the link text and target
content consistent.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yml

Review profile: CHILL

Plan: Pro

Run ID: 9a280ded-b43f-4260-a8d3-c64b61de8e7a

📥 Commits

Reviewing files that changed from the base of the PR and between 759978c and 431f02d.

📒 Files selected for processing (13)
  • en/asgardeo/docs/complete-guides/actions/pre-issue-access-token-action-in-choreo.md
  • en/asgardeo/docs/complete-guides/actions/pre-update-password-action-in-choreo.md
  • en/asgardeo/docs/complete-guides/actions/pre-update-profile-action-in-choreo.md
  • en/asgardeo/docs/guides/monitoring/asgardeo-events.md
  • en/asgardeo/docs/quick-starts/branding-ai.md
  • en/asgardeo/docs/references/operational-policies.md
  • en/identity-server/7.0.0/docs/get-started/about-this-release.md
  • en/includes/guides/authentication/conditional-auth/add-authentications-based-on-api-calls.md
  • en/includes/guides/authentication/conditional-auth/on-demand-silent-password-migration-template.md
  • en/includes/guides/fragments/migrate-users/configure-choreo-for-password-migration.md
  • en/includes/guides/monitoring/index.md
  • en/includes/guides/users/migrate-users/migrate-passwords.md
  • en/includes/references/conditional-auth/api-reference.md
🚧 Files skipped from review as they are similar to previous changes (12)
  • en/asgardeo/docs/references/operational-policies.md
  • en/identity-server/7.0.0/docs/get-started/about-this-release.md
  • en/asgardeo/docs/complete-guides/actions/pre-update-password-action-in-choreo.md
  • en/asgardeo/docs/complete-guides/actions/pre-update-profile-action-in-choreo.md
  • en/asgardeo/docs/quick-starts/branding-ai.md
  • en/asgardeo/docs/complete-guides/actions/pre-issue-access-token-action-in-choreo.md
  • en/includes/guides/fragments/migrate-users/configure-choreo-for-password-migration.md
  • en/includes/guides/monitoring/index.md
  • en/includes/references/conditional-auth/api-reference.md
  • en/asgardeo/docs/guides/monitoring/asgardeo-events.md
  • en/includes/guides/authentication/conditional-auth/on-demand-silent-password-migration-template.md
  • en/includes/guides/authentication/conditional-auth/add-authentications-based-on-api-calls.md


!!! note
Learn how to [configure the external authentication service in Choreo]({{base_path}}/references/tutorials/configure-choreo-for-password-migration/).
Learn how to [configure the external authentication service in WSO2 Developer Platform]({{base_path}}/references/tutorials/configure-choreo-for-password-migration/).

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Update the linked tutorial to match the renamed platform.

The link text now says WSO2 Developer Platform, but the target remains configure-choreo-for-password-migration/, whose supplied content still describes Choreo. Update the target page/path and its content, or retain the old terminology here until the linked page is migrated.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@en/includes/guides/users/migrate-users/migrate-passwords.md` at line 131,
Align the link in the migrate-passwords guide with the renamed platform: either
update the linked tutorial path and its content so it describes WSO2 Developer
Platform, or revert the link text to the existing Choreo terminology until that
migration is complete. Keep the link text and target content consistent.

@rusiru-erandaka

Copy link
Copy Markdown
Author

It seems that 8 other already merged commits are also in your pr. Shall we try updating your branch with master to only include commits from you?

Hi! I think I made the branch history messy while rebasing it with the updated master. I was considering creating a fresh branch from the latest master and applying only my documentation changes, then force-pushing it to the existing PR. Would that be the approach you'd recommend, or would you prefer a different workflow?

@pavinduLakshan

pavinduLakshan commented Jul 20, 2026

Copy link
Copy Markdown
Member

was considering creating a fresh branch from the latest master and applying only my documentation changes, then force-pushing it to the existing PR.

Hi @rusiru-erandaka, that'd also be fine. However try to undo the rebase and properly attempt the rebasing again if possible. that'd make you learn a thing or two about git and would be a good learning experience. ;)

@rusiru-erandaka

Copy link
Copy Markdown
Author

was considering creating a fresh branch from the latest master and applying only my documentation changes, then force-pushing it to the existing PR.

Hi @rusiru-erandaka, that'd also be fine. However try to undo the rebase and properly attempt the rebasing again if possible. that'd make you learn a thing or two about git and would be a good learning experience. ;)

Sure, I will try :)

@rusiru-erandaka

Copy link
Copy Markdown
Author

@pavinduLakshan ayya
is it all ok in PR?? cuz I see some issues related to CI pipeline but i do not have an idea about that.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants