# Web Services API: User Impersonation with ImpersonateUsername parameter

**URL:** <https://discuss.workflowgen.com/t/web-services-api-user-impersonation-with-impersonateusername-parameter/319>\
**Category:** Web API\
**Created:** [January 18, 2014, 4:36am UTC](https://discuss.workflowgen.com/t/web-services-api-user-impersonation-with-impersonateusername-parameter/319 "2014-01-18T04:36:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![wfg-admin](https://yyz2.discourse-cdn.com/flex030/user_avatar/discuss.workflowgen.com/wfg-admin/32/714_2.png) [@wfg-admin](https://discuss.workflowgen.com/u/wfg-admin)\
**Post date:** [January 18, 2014, 4:36am UTC](https://discuss.workflowgen.com/t/web-services-api-user-impersonation-with-impersonateusername-parameter/319/1 "2014-01-18T04:36:41Z")

</div>

As of WorkflowGen version 5.6.3, all user context-based API web methods support impersonation. This means that an authorized user can call a web method on behalf of another user.

**Security**

The impersonation feature is restricted to allowed users as defined in the `ProcessesRuntimeWebServiceAllowedUsers` entry in the `\wfgen\web.config` file.

**Usage**

There are two ways to set the `ImpersonateUsername` value:

- As a querystring parameter; in this example, a list of `todo` actions for `jsmith`:

- As a SOAP header parameter; in this example, to complete an action on behalf of `jsmith`:

---

<div class="post-metadata">

**Author:** ![asullivan78](https://avatars.discourse-cdn.com/v4/letter/a/eb8c5e/32.png) [@asullivan78](https://discuss.workflowgen.com/u/asullivan78)\
**Post date:** [June 12, 2019, 3:47pm UTC](https://discuss.workflowgen.com/t/web-services-api-user-impersonation-with-impersonateusername-parameter/319/2 "2019-06-12T15:47:49Z")

</div>

The ImpersonateUsername parameter is being ignored when using the URL below.

`http://server/wfgen/ws/ProcessesRuntime.asmx/GetActivityInstanceList?query=todo&impersonateusername=jsmith`

Instead it’s using the URL that i’m authenticating with.

---

<div class="post-metadata">

**Author:** ![jianan.hsu](https://yyz2.discourse-cdn.com/flex030/user_avatar/discuss.workflowgen.com/jianan.hsu/32/411_2.png) [@jianan.hsu](https://discuss.workflowgen.com/u/jianan.hsu)\
**Post date:** [June 18, 2019, 10:19pm UTC](https://discuss.workflowgen.com/t/web-services-api-user-impersonation-with-impersonateusername-parameter/319/3 "2019-06-18T22:19:25Z")

</div>

Hi,

I just tested on the latest version. The `impersonateusername` parameter does work fine.

Make sure the username of the person using the impersonation is defined in the WorkflowGen main web.config’s parameter `ProcessesRuntimeWebServiceAllowedUsers` as indicated in the article above.

e.g. `<add key="ProcessesRuntimeWebServiceAllowedUsers" value="wfgen_admin" />`

In this example, `wfgfen_admin` can impersonate `jsmith` when specifying `impersonateusername=jsmith` in the URL.
