API access control

Security Feature

Location / Configuration

Description

Management API access control

UserStartup.cs or API authentication configuration

Access to sensitive operations (license, DB connection, session management) via PowerServer Management APIs is disabled by default and must be explicitly enabled and protected with proper authorization policies.

For detailed instructions, refer to Enable access to APIs.

Windows authentication mode

Project Painter > Security page

Configures authentication modes such as Anonymous, Integrated, or UserPassword for integration with enterprise Windows domain environments.