Skip to Main Content
Integration


This is an IBM Automation portal for Integration products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.


ADD A NEW IDEA

API Connect

Showing 317 of 2301

API Connect Change Detection

We run IBM API Connect environment as ova format and as per enterprise security guidelines we are required to track the changes happening on the system automatically . We were advised to install Tripwire or Symantec DCS equivalent softwares to mat...
about 3 years ago in API Connect 0 Future consideration

Disable XML entitiy expansion for SOAP-based APIs managed using API Connect

Issues with APIc managed APIs were found when running vulnerability tests against published APIs. It was possible for an attacker to use a vulnerability in the configuration of the XML processor, when submitting API requests using SOAP, to poten...
over 6 years ago in API Connect 2 Functionality already exists

Log activities under #/notifications can have the user name added to the log entry.

User details who ever publish/staging/deleting of API/Products are missing logged under the #/notification section of API Manager. User details added to the log entry will be an useful function. The user information is added only whenever a new AP...
almost 7 years ago in API Connect 0 Future consideration

fine-grained permissions for product:manage

A user with the permission product:manage is able to set any of a products lifecycle stage. Our companies API governance process requires a separation of responsibilities, e.g. between users, that develop and publish and API and publish it via pip...
over 3 years ago in API Connect 0 Future consideration

fine-grained permissions for member:manage

The member:manage permission in API manager allows a user to assign any role to himself or other members. This can lead to privilege escalation, if the member:manage permission needs to be assigned to different role than admin.The member:manage pe...
over 3 years ago in API Connect 0 Future consideration

API developers on space level must develop APIs in serverside API Designer

We use catalogs with spaces. Teams allways publish products in a space.API developers that are members on space level only should be able to use the serverside API Designer and they should only be able to view and edit their own apis/products and ...
over 3 years ago in API Connect 0 Future consideration

JWT-Genarate Policy doesn't have option to define custome headers

Unfortunately, as of right now we don't have these custom JWT headers supported in the assembly JWT-Generate policy
over 3 years ago in API Connect 0 Future consideration

Language support for Activation Link, Member invitation Link and Password Link Redirect

When the user submit the organization request, member invitation request and password reset at different language, when the email is received, he or she will expect to view the page in the same language. Apparently, it is always in the default lan...
over 3 years ago in API Connect 0 Future consideration

Email Notification Alias support for Member Invitation

For member invitation email notification, it only have org, activation link and expireAt parameter. In the security perspective, it is better to have the Sender name and Sender email to identify who is sending/inviting the membership to the recipi...
over 3 years ago in API Connect 0 Future consideration

v10 need mechanism to expire 3rd Party Oauth provider introspection result cache

ISAM is used as 3rd party Oauth provider - we leverage the /introspect result cache capability to relief load to ISAM - and use Cache-control max-age to reflect the lifespan of the Access Token. We need a mechanism to expire the cached result for ...
over 3 years ago in API Connect 0 Future consideration