The Application-to-Application (A2A) service allows external applications to retrieve managed credentials from SPP without user interaction and without exposing passwords to operators. Authentication is certificate-based: the calling application presents a client certificate, and a per-account API key authorises retrieval of the specific credential.
Starting with SPP 8.x / A2A API v4, the service supports four credential types:
|
Type |
Description |
|---|---|
|
|
Account password (default) |
|
|
SSH private key |
|
|
API key(s) assigned to the account |
|
|
File credential |
A2A also supports Bidirectional mode (writing credentials back to SPP) and an Access Request Broker mode for impersonating SPP users to create access requests programmatically.
Resolution steps are available in the attached document (Configuring Safeguard A2A and Credential Requests for Privileged Passwords.docx), please download the file below.
© 2026 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center