# Mapping Plain auth Token in SailPoint ISC Web Services Connector

**URL:** <https://developer.sailpoint.com/discuss/t/mapping-plain-auth-token-in-sailpoint-isc-web-services-connector/195780>\
**Category:** SHF Discussion and Questions\
**Tags:** webservice-connector, connectors, identity-security-cloud\
**Created:** [February 10, 2026, 5:54pm UTC](https://developer.sailpoint.com/discuss/t/mapping-plain-auth-token-in-sailpoint-isc-web-services-connector/195780 "2026-02-10T17:54:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![pradipniladhe1](https://avatars.discourse-cdn.com/v4/letter/p/e56c9b/32.png) [@pradipniladhe1](https://developer.sailpoint.com/discuss/u/pradipniladhe1)\
**Post date:** [February 10, 2026, 5:54pm UTC](https://developer.sailpoint.com/discuss/t/mapping-plain-auth-token-in-sailpoint-isc-web-services-connector/195780/1 "2026-02-10T17:54:51Z")

</div>

Hi Team,

We are working with the Web Services (SaaS) connector. Our authentication REST API token endpoint returns the access token directly as a plain/JWT string (for example: “abcsjjdk–d”) rather than as a JSON object.

In SailPoint ISC, the connector typically expects a JSON response and allows token extraction using a JSONPath such as $application.accessToken$. However, since our token endpoint returns only the raw token string this approach does not work for us.

After reviewing forum responses, we switched to the Custom Authentication option. We are still trying to understand how to correctly map the token in the Test Connection response mapping and then pass that token into the Create User HTTP operation for authorization?

Thanks,

---

<div class="post-metadata">

**Author:** ![mcheek](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/mcheek/32/23705_2.png) [@mcheek](https://developer.sailpoint.com/discuss/u/mcheek)\
**Post date:** [February 10, 2026, 6:36pm UTC](https://developer.sailpoint.com/discuss/t/mapping-plain-auth-token-in-sailpoint-isc-web-services-connector/195780/2 "2026-02-10T18:36:06Z")

</div>

~~You could use a web service before operation rule to execute the get token call. You’d get your credentials from the application class, make a call to the token endpoint using the restClient class, then add the access token to the request headers using the requestEndPoint class~~

EDIT: I just realized this is a web services SaaS connector which doesn’t use the before/after operation rules like the VA-based one does. For that you’d have to use some sort of endpoint customizer to make this work

> **[Endpoint Customization](https://documentation.sailpoint.com/connectors/saas/web_services/help/saas_connectivity/web_services/endpoint_customization.html)**
>
> SailPoint Connectors Documentation

---

<div class="post-metadata">

**Author:** ![pradipniladhe1](https://avatars.discourse-cdn.com/v4/letter/p/e56c9b/32.png) [@pradipniladhe1](https://developer.sailpoint.com/discuss/u/pradipniladhe1)\
**Post date:** [February 11, 2026, 1:31pm UTC](https://developer.sailpoint.com/discuss/t/mapping-plain-auth-token-in-sailpoint-isc-web-services-connector/195780/3 "2026-02-11T13:31:49Z")

</div>

Thank you @mcheek

I will try this approach.

Also I was going through SailPoint documentation under _Custom Authentication_, I tried adding an attribute to the connector and storing the complete token response in that attribute. However, not sure whether this is actually possible. If anyone has any insights or experience with this approach?

Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [April 12, 2026, 1:32pm UTC](https://developer.sailpoint.com/discuss/t/mapping-plain-auth-token-in-sailpoint-isc-web-services-connector/195780/4 "2026-04-12T13:32:42Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
