Skip to content

Canton gRPC Auth — Setup & Onboarding Guide

Date: August 2026

The Outer Sunset ingester streams ledger data over the gRPC Ledger API from its clients’ Canton participant nodes. Each client operates its own validator on independent infrastructure, so the ingester connects to a separate node per client.

Securing and exposing the Ledger API is the validator operator’s responsibility. Implementation details such as infrastructure, reverse proxies, firewalls, and hosting topology are outside the scope of this guide.


This section covers the connection between the Outer Sunset ingester and a client’s participant node, and the values the operator must provide to establish it.

The Outer Sunset ingester is a machine-to-machine service that streams ledger data over gRPC. It opens a read-only channel to your participant node’s Ledger API and continuously streams updates for the parties it is permitted to read.

To connect, it needs to reach your Ledger API endpoint and present a credential proving it may read, depending on how your node is set up.

If your node requires authentication before it accepts a gRPC connection, you’ll need to give us the credentials to connect. What we require depends on the mechanism your node uses:

The ingester obtains a token from your identity provider and presents it on each gRPC call, refreshing it before it expires. The client ID and secret identify a machine-to-machine client on your identity provider whose identity is authorized to read on the node. The ingester expects these fields:

Required

Value Example Notes
Token endpoint https://idp.acme.com/realms/canton/protocol/openid-connect/token Where the ingester requests tokens.
Issuer https://idp.acme.com/realms/canton The iss your node trusts; also used for discovery.
Client ID outersunset-ingester
Client Secret

Optional

Value Example Notes
Audience canton-ledger Only if your IdP requires an audience request parameter (e.g. Auth0).

Read rights. The service-account user backing the client must exist as a participant user with read access — either readAsAnyParty, or the specific parties you want ingested. Without it, a valid token is still rejected with PermissionDenied.

If your node does not enforce authentication, or uses a different mechanism, please contact us.

Some clients restrict access to their Ledger API behind an IP allowlist or firewall. Where such controls are in place, the operator must add the Outer Sunset ingester’s egress IP address to the allowlist before a connection can be established. The egress IP address is provided during the onboarding flow described in Section III.

Before connecting Outer Sunset, confirm:

  • Ledger API endpoint is reachable from our ingester’s egress IP.
  • The credentials you’ve shared can authenticate and read on the node. For JWT, this means the token endpoint, issuer, client ID, and client secret, plus audience if your IdP requires it.