Application Authentication API
Getting Started
The Application Authentication is an oAuth 2.0 token-based authentication. One set of credentials is created for each DSP in each environment.
❗ ❗ When starting work on a DCP API, we need to request access by creating a certification ticket in Jira, as described in the section Certification Activities with Jira. ❗ ❗
If you already started work on an API and you lost access, create a support ticket as described in the section Open a Support Ticket.
The credentials will normally never expire or be revoked (unless you quit DCP).
However, the credentials may change, so your implementation must allow you to easily change and use new credentials.
The access token is valid for 30 minutes! (1799 seconds)
Where to Start? Read Me First!
Before you start working on this API, you need to read the following sections if you haven't already looked at them:
Technical Information
Characteristics
API Type | DSP Type | DCP Version | Complexity |
|---|---|---|---|
Get data from BRP | DMS | V3 - International | Low |
Send data to BRP | CRM | V4 - North America | A bit more |
Transaction with BRP | | | Somewhat more |
Authentication
To call the Application Authentication API, you need the client_id and client_secret provided to you by the DCP Team.
Make sure to use the client_id and client_secret to match the environment in which the API is called!
Base URL
Test | https://qa-cloud-api.brp.com/dcp |
|---|---|
Production | https://cloud-api.brp.com/dcp |
API Reference
curl --request POST 'https://qa-cloud-api.brp.com/dcp/authentication/app/token' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode 'grant_type=client_credentials' \
--data-urlencode 'client_id=REPLACE_ME_CLIENT_ID' \
--data-urlencode 'client_secret=REPLACE_ME_CLIENT_SECRET'curl --request POST 'https://qa-cloud-api.brp.com/dcp/authentication/app/verify' \
--header 'Authorization: Bearer ACCESS_TOKEN' \
--data-raw ''How-To
This section provides information on how to obtain specific results with the API.
Get an Access Token
Replace the REPLACE_ME_CLIENT_ID and REPLACE_ME_CLIENT_SECRET with the values corresponding to your credentials in the environment where the call is made.
If the REPLACE_ME_CLIENT_ID and REPLACE_ME_CLIENT_SECRET credentials are valid, the response provides you with an access_token.
The access token is valid for 30 minutes! (1799 seconds)
curl --request POST 'https://qa-cloud-api.brp.com/dcp/authentication/app/token' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode 'grant_type=client_credentials' \
--data-urlencode 'client_id=REPLACE_ME_CLIENT_ID' \
--data-urlencode 'client_secret=REPLACE_ME_CLIENT_SECRET'Verify an Access Token
After getting your bearer access_token, you can verify it by calling the API verify endpoint.
The API response will provide the application name if the token is valid and not expired.
curl --request POST 'https://qa-cloud-api.brp.com/dcp/authentication/app/verify' \
--header 'Authorization: Bearer REPLACE_ME_ACCESS_TOKEN' \
--data-raw ''Error Handling
This section presents various scenarios of improper or wrong calls, which result in error messages and improper results.
400 Bad Request
The grant_type value is either invalid or missing.
Check your call and make sure to include the proper grant_typevalue.
401 Unauthorized
The 401 Unauthorized status code is generally caused by the client_id or client_secret being invalid.
Another possible reason is that a request parameter is missing.
To solve this problem, verify that you are using the proper credential set for the environment in which you are calling the DCP API.
Refer to the section Environments for information on the available environments.
DSP Requirements
Functional Requirements
ID | Type | |
|---|---|---|
1 | Mandatory | The access_token must be automatically refreshed every 29 minutes |
Certification Activities
There are no specific certification activities for the Application Authentication API, it is validated through the DCP API using Application Authentication.
Postman
This section describes what is available in Postman to explore the API.
Environments
A Postman environment is available to try the Application Authentication API. This Postman environment contains variables that are used by the queries and are configured to connect to the test environment.
Test - DSP Environment
Collections
The DSP - Application Authentication collection contains examples of calls to the API to get an access token and validate the token.