Authentication
In order to use FieldAgent's GraphQL API, an application must first authenticate with FieldAgent to obtain an access token. The access token must be sent in the Authorization header of GraphQL API HTTP requests.
Before an application can authenticate with FieldAgent via OAuth2, it must be registered with Sentera. Submit an API integration request to begin this process. Sentera will configure the appropriate OAuth flow and provide the credentials required by your application.
FieldAgent supports two OAuth2 flows for new API integrations:
Authorization Code Grant Flow
Use the authorization code grant flow when a FieldAgent user is present and your application needs to access data on that user's behalf. The user signs into FieldAgent, approves access, and is redirected back to your application. This flow returns an access token and a refresh token.
See Authorization Code Grant Flow for the complete sequence, request examples, token refresh, and revocation guidance.
Client Credentials Grant Flow
Use the client credentials grant flow for an unattended server-to-server integration where no FieldAgent user is present to sign in or approve each connection. Sentera associates the OAuth application with a dedicated FieldAgent integration user, and your service authenticates using its client ID and client secret. This flow returns an access token but not a refresh token.
See Client Credentials Grant Flow for the complete sequence, token request, API request, renewal, and security guidance.
Legacy Authentication
For details on using the legacy authentication endpoint, click here. Not to be used with new client applications.