# Web Service VA Based Custom Authentication

**URL:** <https://developer.sailpoint.com/discuss/t/web-service-va-based-custom-authentication/200695>\
**Category:** SHF Discussion and Questions\
**Tags:** webservice-connector, identity-security-cloud, rules, aggregation\
**Created:** [March 26, 2026, 12:32pm UTC](https://developer.sailpoint.com/discuss/t/web-service-va-based-custom-authentication/200695 "2026-03-26T12:32:43Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![laxman\_angadala](https://avatars.discourse-cdn.com/v4/letter/l/43a26b/32.png) [@laxman\_angadala](https://developer.sailpoint.com/discuss/u/laxman_angadala)\
**Post date:** [March 26, 2026, 12:32pm UTC](https://developer.sailpoint.com/discuss/t/web-service-va-based-custom-authentication/200695/1 "2026-03-26T12:32:43Z")

</div>

Hello Team,

I am currently working on a Web Services VA-based connector and encountering the following issues:

1. I am using custom authentication, where I receive a `sessionID` in the response. This `sessionID` needs to be reused to authenticate subsequent endpoint calls.

2. When testing in Postman, the “Get All Users” API returns the expected response. However, within SailPoint, the results are not as expected.

3. During account aggregation, I have implemented Before and After rules for pagination. The issue is that a new `sessionID` is being generated for each request, instead of reusing the existing session.

Additional Information:

- Maximum number of concurrent logins allowed for the service account: 10

- Default session timeout for a single API login: 60 minutes

Could you please assist in identifying the root cause and suggest a solution?

Thank you.

---

<div class="post-metadata">

**Author:** ![MattUribe](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/matturibe/32/20300_2.png) [@MattUribe](https://developer.sailpoint.com/discuss/u/MattUribe)\
**Post date:** [March 26, 2026, 2:58pm UTC](https://developer.sailpoint.com/discuss/t/web-service-va-based-custom-authentication/200695/2 "2026-03-26T14:58:21Z")

</div>

I don’t know what your configuration looks like, but for me, custom authentication requires the authentication type to be set to “Custom Authentication”, and an HTTP operation with operation type “Custom Authentication”. Then you store the response, sessionID in this case, so that it can be reused in the remaining requests, using response mapping or an afterOperation rule. Finally, under Additional Settings, fill in any necessary errors so that ISC knows when to re-auth. For example:

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/b/9/b9bc7f68a9e21b1edba9ee76aad5276e9914e33f.png)

If you are putting the authentication step in your account aggregation operations, then it will re-auth for every page, like you are describing.

Matt

---

<div class="post-metadata">

**Author:** ![BBR1](https://avatars.discourse-cdn.com/v4/letter/b/c57346/32.png) [@BBR1](https://developer.sailpoint.com/discuss/u/BBR1)\
**Post date:** [March 26, 2026, 3:16pm UTC](https://developer.sailpoint.com/discuss/t/web-service-va-based-custom-authentication/200695/3 "2026-03-26T15:16:30Z")

</div>

> [@laxman\_angadala](#):
>
> Postman, the “Get All Users” API returns the expected response. However, within SailP

If SailPoint is not returning the desired results,

1.have you checked the VA logs.

2.You can also check if the placeholders are incorrect or if any headers are missing.

---

<div class="post-metadata">

**Author:** ![PhilRawlings1](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/philrawlings1/32/37266_2.png) [@PhilRawlings1](https://developer.sailpoint.com/discuss/u/PhilRawlings1)\
**Post date:** [March 26, 2026, 3:27pm UTC](https://developer.sailpoint.com/discuss/t/web-service-va-based-custom-authentication/200695/4 "2026-03-26T15:27:14Z")

</div>

Many questions,  
Why not use the SaaS connector instead, but otherwise. do you want to show us your build config so that we can help you better

---

<div class="post-metadata">

**Author:** ![lampard08](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/lampard08/32/32646_2.png) [@lampard08](https://developer.sailpoint.com/discuss/u/lampard08)\
**Post date:** [March 26, 2026, 3:53pm UTC](https://developer.sailpoint.com/discuss/t/web-service-va-based-custom-authentication/200695/5 "2026-03-26T15:53:53Z")

</div>

> ## **Operational Trigger Timing**
> 
> The point within an operation that custom authentication is triggered may vary depending on the operation you configure.
> 
> - When performing a Test Connection, the system first executes the custom authentication operation or endpoint. This step is important as it retrieves the `customaccesstoken` or other authentication-related attributes, which are then utilized in the headers or body of the Test Connection operation.
> 
> - For other operations, the system first verifies whether the `customaccesstoken` or any related authentication attributes are saved. If they are, it utilizes them. If not, it executes the custom authentication operation or endpoint to generate the `customaccesstoken` or any related authentication attributes.
> 
> If an operation fails, the system checks the returned exception code. If the code is `401` or if the error code/message matches one is configured in the **HTTP Error** field on the Additional Settings menu page, it triggers a custom authentication operation or endpoint. This process generates a `customaccesstoken` or any related authentication attributes. For more information on the HTTP Error field, refer to [HTTP Errors](https://documentation.sailpoint.com/connectors/webservices/help/integrating_webservices/additional_settings.html#HTTP%C2%A0Err).

> **[Custom Authentication](https://documentation.sailpoint.com/connectors/webservices/help/integrating_webservices/idn_config_for_custom_authentication.html)**
>
> SailPoint Connectors Documentation

by default, the connector only gets the new session every time for test connection op and other ops reuse unless you configure the error msg explicitly to catch it and get new session.

can you post your custom auth config and also curious about the rules for pagination. if you can post the rule.

---

<div class="post-metadata">

**Author:** ![laxman\_angadala](https://avatars.discourse-cdn.com/v4/letter/l/43a26b/32.png) [@laxman\_angadala](https://developer.sailpoint.com/discuss/u/laxman_angadala)\
**Post date:** [March 27, 2026, 9:01am UTC](https://developer.sailpoint.com/discuss/t/web-service-va-based-custom-authentication/200695/6 "2026-03-27T09:01:55Z")

</div>

@MattUribe Thank you for your response

My Scenario API giving always 200 Ok Success code.

---

<div class="post-metadata">

**Author:** ![laxman\_angadala](https://avatars.discourse-cdn.com/v4/letter/l/43a26b/32.png) [@laxman\_angadala](https://developer.sailpoint.com/discuss/u/laxman_angadala)\
**Post date:** [March 27, 2026, 9:03am UTC](https://developer.sailpoint.com/discuss/t/web-service-va-based-custom-authentication/200695/7 "2026-03-27T09:03:26Z")

</div>

@PhilRawlings1 Thanks for reply,

It is Inhouse application they don’t have SaaS Connector for this one

---

<div class="post-metadata">

**Author:** ![PhilRawlings1](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/philrawlings1/32/37266_2.png) [@PhilRawlings1](https://developer.sailpoint.com/discuss/u/PhilRawlings1)\
**Post date:** [March 27, 2026, 9:05am UTC](https://developer.sailpoint.com/discuss/t/web-service-va-based-custom-authentication/200695/8 "2026-03-27T09:05:26Z")

</div>

Ok.  
So the build works in postman, but not in Sailpoint?

---

<div class="post-metadata">

**Author:** ![laxman\_angadala](https://avatars.discourse-cdn.com/v4/letter/l/43a26b/32.png) [@laxman\_angadala](https://developer.sailpoint.com/discuss/u/laxman_angadala)\
**Post date:** [March 27, 2026, 9:10am UTC](https://developer.sailpoint.com/discuss/t/web-service-va-based-custom-authentication/200695/9 "2026-03-27T09:10:50Z")

</div>

The issue was resolved by passing the Session ID in the request headers before the operation rule executes and then using that same Session ID in the after-operation rule to properly close the session for each HTTP call.

**But Accounts Scanned showing more than actual accounts.**

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/b/f/bf1174cf03bd56414696b7d10bf9ecf9195099bc.png)

**Original Accounts Count:**

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/1/4/14dc315f60fad46838274b26e4fb0814d45642ee.png)

---

<div class="post-metadata">

**Author:** ![PhilRawlings1](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/philrawlings1/32/37266_2.png) [@PhilRawlings1](https://developer.sailpoint.com/discuss/u/PhilRawlings1)\
**Post date:** [March 27, 2026, 9:20am UTC](https://developer.sailpoint.com/discuss/t/web-service-va-based-custom-authentication/200695/10 "2026-03-27T09:20:18Z")

</div>

Which of the two values is accurate? if either

---

<div class="post-metadata">

**Author:** ![laxman\_angadala](https://avatars.discourse-cdn.com/v4/letter/l/43a26b/32.png) [@laxman\_angadala](https://developer.sailpoint.com/discuss/u/laxman_angadala)\
**Post date:** [March 27, 2026, 1:46pm UTC](https://developer.sailpoint.com/discuss/t/web-service-va-based-custom-authentication/200695/11 "2026-03-27T13:46:39Z")

</div>

**Original Accounts Count:**

[![image](https://global.discourse-cdn.com/sailpoint/original/3X/1/4/14dc315f60fad46838274b26e4fb0814d45642ee.png)](https://global.discourse-cdn.com/sailpoint/original/3X/1/4/14dc315f60fad46838274b26e4fb0814d45642ee.png "image")

---

<div class="post-metadata">

**Author:** ![MattUribe](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/matturibe/32/20300_2.png) [@MattUribe](https://developer.sailpoint.com/discuss/u/MattUribe)\
**Post date:** [March 27, 2026, 2:18pm UTC](https://developer.sailpoint.com/discuss/t/web-service-va-based-custom-authentication/200695/12 "2026-03-27T14:18:23Z")

</div>

I would suspect something with your before and after rules, if the object count has changed that much.

Back to your API always returning a 200 response code, doesn’t it still provide a message in the response that your not authenticated? You just need to make sure that message is configured in the Additional Settings page. @lampard08 posted the link to the relevant doc.

Also, as @BBR1 mentioned, you need to be checking your VA logs to see what exactly is happening before, during, and after each of the configured HTTP operations. I like to use something like this to more easily navigate the VA logs:

```auto
cat /home/sailpoint/log/ccg.log | grep $1 | grep $2 | jq | grep --color=always 'message\|messageType\|timestamp\|Application' | less -R

```

The $1 and $2 are just placeholders for source name and timestamp, but you can filter on anything you like. The jq makes the json more readable. Using less makes the output scrollable/searchable. When you are using less, the -R helps to preserve the formatting the jq provides.

Hope that helps.

Matt

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [May 26, 2026, 2:18pm UTC](https://developer.sailpoint.com/discuss/t/web-service-va-based-custom-authentication/200695/13 "2026-05-26T14:18:37Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
