Canton gRPC Auth — Setup & Onboarding Guide
Date: August 2026
I. Overview
Section titled “I. Overview”The Outer Sunset ingester streams ledger data over the gRPC Ledger API from its clients’ Canton participant nodes. Each client operates its own validator on independent infrastructure, so the ingester connects to a separate node per client.
Securing and exposing the Ledger API is the validator operator’s responsibility. Implementation details such as infrastructure, reverse proxies, firewalls, and hosting topology are outside the scope of this guide.
II. Connecting Outer Sunset to your node
Section titled “II. Connecting Outer Sunset to your node”This section covers the connection between the Outer Sunset ingester and a client’s participant node, and the values the operator must provide to establish it.
A — What the ingester does
Section titled “A — What the ingester does”The Outer Sunset ingester is a machine-to-machine service that streams ledger data over gRPC. It opens a read-only channel to your participant node’s Ledger API and continuously streams updates for the parties it is permitted to read.
To connect, it needs to reach your Ledger API endpoint and present a credential proving it may read, depending on how your node is set up.
B — Authentication
Section titled “B — Authentication”If your node requires authentication before it accepts a gRPC connection, you’ll need to give us the credentials to connect. What we require depends on the mechanism your node uses:
a. JWT (jwt-jwks)
Section titled “a. JWT (jwt-jwks)”The ingester obtains a token from your identity provider and presents it on each gRPC call, refreshing it before it expires. The client ID and secret identify a machine-to-machine client on your identity provider whose identity is authorized to read on the node. The ingester expects these fields:
Required
| Value | Example | Notes |
|---|---|---|
| Token endpoint | https://idp.acme.com/realms/canton/protocol/openid-connect/token |
Where the ingester requests tokens. |
| Issuer | https://idp.acme.com/realms/canton |
The iss your node trusts; also used for discovery. |
| Client ID | outersunset-ingester |
|
| Client Secret |
Optional
| Value | Example | Notes |
|---|---|---|
| Audience | canton-ledger |
Only if your IdP requires an audience request parameter (e.g. Auth0). |
Read rights. The service-account user backing the client must exist as a participant user with read access — either
readAsAnyParty, or the specific parties you want ingested. Without it, a valid token is still rejected withPermissionDenied.
b. No auth, or another mechanism
Section titled “b. No auth, or another mechanism”If your node does not enforce authentication, or uses a different mechanism, please contact us.
C — Network access
Section titled “C — Network access”Some clients restrict access to their Ledger API behind an IP allowlist or firewall. Where such controls are in place, the operator must add the Outer Sunset ingester’s egress IP address to the allowlist before a connection can be established. The egress IP address is provided during the onboarding flow described in Section III.
D — Operator checklist
Section titled “D — Operator checklist”Before connecting Outer Sunset, confirm:
- Ledger API endpoint is reachable from our ingester’s egress IP.
- The credentials you’ve shared can authenticate and read on the node. For JWT, this means the token endpoint, issuer, client ID, and client secret, plus audience if your IdP requires it.