---
nav: wcp_docs
parent_url: /wcp_docs/
title: REST API Authentication
layout: subsection
---

Extend and Orchestrate require OAuth to authenticate calls to Workday and external REST APIs. The base path of the Workday REST API URL must use the [API Gateway](/wcp_docs/dlh1653340161856.html), which manages the authentication and routes the REST API requests to the correct tenant for Workday security authorization.

## <a id="section_1"></a>REST API Authentication in Extend Apps

To authenticate Workday REST API calls from Extend pages and orchestrations, choose an authentication scheme that defines the type of credentials sent to the API Gateway. See the Orchestration Authentication and Endpoint Authentication sections in [Concept: Extend App Security](/wcp_docs/vel1628698852360.html).

To authenticate external REST API calls from an Extend app, see [Call External REST APIs in Extend Apps](/wcp_docs/GUID-10a25b3e-5e1b-4d78-8c5e-b61c331048d2-enHYPHENus.html).

## <a id="section_workday_extend"></a>REST API Authentication in Integration Apps

To authenticate Workday and external REST API calls from an Integration app, see [Concept: Integration App Security](/wcp_docs/GUID-3586727d-613d-4d19-a27b-7e51c70c9ca8.html) and [Create Orchestration Credentials](/wcp_docs/GUID-d93db6e9-f07a-4e89-9ad0-2070f54c3286.html).

## <a id="section_orchestrate"></a>REST API Authentication in Integrations

To authenticate Workday and external REST API calls from external apps or integrations, register your API client on the Developer Site and choose an OAuth authentication flow to generate the access token. See [Concept: Authorization Flows](/wcp_docs/axg1518029552225.html).

### Related Information

[Concept: Workday Cloud Platform API Gateway](/wcp_docs/GUID-6141e955-7cfe-4bee-b736-73a108d19d9f-enHYPHENus.html)

