# Configuration

Enable and configure Soracom Endorse.

> [!WARNING]
>
> Enabling Endorse will incur fees based on the number of devices where the service is enabled. Refer to the [Pricing & Fee Schedule](https://docs.soracom.io/en/pricing) for more information.

Soracom Endorse settings are found in Soracom Air for Cellular group settings.

1. Sign in to the **[User Console](https://console.soracom.io/?coverage_type=g)**. From the **☰ Menu**, open the **Groups** screen.

2. From the list of groups, click the **Name** of the group you want to configure to open its settings page.

   > [!WARNING]
   >
   > You can also open the group settings page directly from the **SIM Management** screen. Simply find a SIM that currently belongs to the group you want to configure, then click the group name.

3. From the **Basic Settings** tab, click the **SORACOM Endorse** panel to expand its settings.

   ![Endorse configuration](https://docs.soracom.io/_astro/endorse-options.Jsqq0d32_ZnMXX0.webp)

4. Enable Endorse by switching the option to **ON**.

5. Configure any of the **Options** below.

6. Click the **Save** button at the bottom of the panel.

Once Endorse has been enabled and configured, it will be immediately available to any Air for Cellular subscriber that belongs to the group.

## Options

- **Items to include in token** - Adds the selected parameters to the token payload data.

  - **SIM ID** - Adds the SIM ID to the token.
  - **IMSI** - Adds the subscriber IMSI to the token.
  - **IMEI** - Adds the device IMEI to the token.
  - **MSISDN** - Adds the number of the subscriber to the token.
  - **Request parameters** - Adds additional parameters passed from the HTTP token request. For example, by specifying a query string `?user=sora` in the initial HTTP GET token request, the parameter `"user": "sora"` will be included in the token.

- **Token timeout** - The validity period in seconds of the token from time of issue.

- **Allow origin** - Adds an `Access-Control-Allow-Origin` header to the HTTP response for CORS (Cross-Origin Resource Sharing). When accessing Endorse through an external resource (such as an AJAX request), you can specify the external origin to allow the request.

- **Authorized redirect URLs** - A list of redirect URLs to allow when an HTTP `GET` request includes a `redirect_url` parameter in the query string (see Advanced Usage).

## Advanced Configuration

Endorse can also be configured through the Soracom API or CLI by using the **SoracomEndorse** namespace.

### Configuration Structure

```json
"SoracomEndorse": {
  "enabled": true|false,
  "parametersToEndorse" {
    "simId": true|false,
    "imsi": true|false,
    "imei": true|false,
    "msisdn": true|false,
    "requestParameters": true|false
  },
  "tokenTimeoutSeconds": 600,
  "allowOrigin": "",
  "authorizedRedirectUrls": []
}
```

### Parameters

Enable or disable Endorse:

- **key** (_string_, required) - `enabled`
- **value** - (_boolean_, default: `false`) - Enables or disables Endorse.

Modify which parameters are included in Endorse tokens.

- **key** (_string_, required) - `parametersToEndorse`

- **value** (_object_, required) - Configure Endorse token parameters.

  - **simId** (_boolean_, default `false`) - Includes or excludes SIM ID from token parameters.
  - **imsi** (_boolean_, default `false`) - Includes or excludes subscriber IMSI from token parameters.
  - **imei** (_boolean_, default `false`) - Includes or excludes device IMEI from token parameters.
  - **msisdn** (_boolean_, default `false`) - Includes or excludes subscriber MSISDN from token parameters.
  - **requestParameters** (_boolean_, default `false`) - Includes or excludes query string parameters from token parameters.

Modify the token TTL:

- **key** (_string_, required) - `tokenTimeoutSeconds`
- **value** (_integer_, default: `600`) - Length of time (in seconds) tokens will be valid from time of issue.

Modify URL for use in CORS headers:

- **key** (_string_, required) - `allowOrigin`
- **value** (_string_, required) - The URL to set in the `Access-Control-Allow-Origin` response. When blank, CORS headers are disabled.

Modify URLs that are authorized for redirection from Endorse:

- **key** (_string_, required) - `authorizedRedirectUrls`
- **value** (_array_ of _strings_, required) - Array of URLs where redirection is authorized. Used in conjunction with a `redirect_url` query parameter.

### Sample

```json
[
  {
    "key": "enabled",
    "value": true
  },
  {
    "key":"parametersToEndorse",
    "value": {
      "simId": true,
      "imsi": true,
      "imei": true,
      "msisdn": false,
      "requestParameters": true
    }
  },
  {
    "key": "tokenTimeoutSeconds",
    "value": 600
  },
  {
    "key": "allowOrigin",
    "value": "https://soracom.io"
  },
  {
    "key": "authorizedRedirectUrls",
    "value": ["https://soracom.io", "http://localhost:3000"]
  }
]
```
