Hi Aleksandr,
the genToken should only work for accounts not created by other identity providers like myID or Entra.
The password for the SSO login is not stored in simplifier. Therefore only local accounts will work.
For technical Users I would suggest setting up one for each intended task, with as little permission and the longest passwords as possible. The credentials should never be exposed to any users (e.g. client side). Additionally, there should be a valid inbox, in order to check possible received emails (This is especially relevant if the user is used in workflows). If none is avialable, this could be the mail of the responsible person/admin using the following syntax: ad.min+techUserUsecase@example.com (most Email providers support this, but maybe not all). In case the TechUser is used in Simplifier itself, it should be added as a login method instead of being hardcoded into a Connector/BO, if possible.
Kind Regards
Lukas