Autenticación y Credenciales
Arquitectura y Autenticación
Para entender cómo funciona la autenticación de la API DCP, necesitas una visión general de la arquitectura de la API DCP, que se muestra a continuación.

Cuando llamas a una API DCP, el punto de entrada es el Adaptador DCP, la única API pública de DCP.
Cuando se llama, el Adaptador DCP primero valida tus credenciales de Autenticación de Aplicación. Consulta la sección siguiente para más información.
Si tus credenciales son válidas, tu solicitud se enruta a la API de proceso de DCP correspondiente, que luego llama a los sistemas backend de BRP.
Sin embargo, para que tu solicitud tenga éxito, debes estar autorizado para usar la API DCP; de lo contrario, recibirás un estado 401 Unauthorized.
❗ ❗ Al comenzar a trabajar en una API DCP, debemos solicitar acceso creando un ticket de certificación en Jira, como se describe en la sección Actividades de Certificación con Jira. ❗ ❗
Si ya comenzaste a trabajar en una API y perdiste acceso, crea un ticket de soporte como se describe en la sección Abrir un Ticket de Soporte.
Authentication Types
The DCP APIs are using 2 types of authentication:
- Most APIs use application authentication.
- A few specific APIs use dealer authentication.
In the Catálogo de API section, the authentication type used by each API is provided.
Application Authentication
The application Authentication is an oAuth 2.0 token-based authentication. One set of credentials is created for each DSP in each environment.
Note that if you have both a DMS and a CRM and integrate the 2 types of DCP APIs, four sets of credentials are created for you:
- DMS in test
- DMS in production
- CRM in test
- CRM in production
The DMS and CRM credentials are not interchangeable!
❗ ❗ When starting work on a DCP API, we need to request access by creating a certification ticket in Jira, as described in the section Certification Activities with Jira. ❗ ❗
If you already started work on an API and you lost access, create a support ticket as described in the section Open a Support Ticket.
The credentials will normally never expire or be revoked (unless you quit DCP).
However, the credentials may change, so your implementation must allow you to easily change and use new credentials.
Get Access Token
You get the Application Authentication oAuth 2.0 token by calling the API de Autenticación de Aplicaciones.
The received oAuth 2.0 token is used as a bearer token to authenticate the DSP when calling the DCP APIs.
The oAuth 2.0 token will expire after 30 minutes from the time the token is granted.
Once expired, a status code 401 is returned when calling a DCP API.
You should implement an automated process to generate a new token every 25 minutes.

Dealer Authentication
Dealer Authentication is more complex and is used when the DSP and dealer must be identified.
The first step is for the dealer to log in using its BOSSweb account, which is the BRP dealer portal implemented using Salesforce. An authorization code is returned to the DSP.
El segundo paso es guardar el token de actualización recibido.
El tercer paso es obtener un token de acceso oAuth 2.0 utilizando el código de autorización recibido.
Inicio de sesión en DSP BOSSWeb
Para probar su mecanismo de Autenticación de Distribuidor y las API de DCP utilizando la Autenticación de Distribuidor, se crea para usted una cuenta BOSSWeb con un número de distribuidor específico en el entorno de prueba.
La información sobre esta cuenta BOSSWeb de prueba le es enviada por el equipo de DCP.
¡No se creará una cuenta BOSSweb para usted en producción!
Configuración
Antes de llamar al servicio de Autenticación de Distribuidor, se deben crear credenciales y configurar las URL de redirección para el DSP en Salesforce. El equipo de DCP crea un conjunto de credenciales para cada entorno, y el DSP utiliza estas credenciales para llamar al servicio de Gestión de Cuentas de Distribuidor.
El DSP debe proporcionar una URL de redirección para cada entorno.
Salesforce utiliza la URL de redirección para devolver el código de autorización cuando el distribuidor inicia sesión.
❗ ❗ The URL used in calling the API de Autenticación de Concesionarios must match EXACTLY the one you provided for the configuration ❗ ❗
If the URL you provided for the production environment is https://site, you have to use the same URL in the redirect parameter in the call to the API de Autenticación de Concesionarios.
If you use https://site/ or https://Site in the redirect parameter, you will receive an error:
Obtain Authorization Code
The DSP initiates the authentication process and retrieves an authorization code by calling the Dealer Account Management service.
The authorization code is returned through the redirect URL, and the DSP uses it to get an access token.
The authorization code will expire within 5 minutes.
Once expired, a status code 401 is returned when calling a DCP API.
Get Access Token
The authorization token is used to call the Dealer Account Management service to get access and refresh tokens.
The received oAuth 2.0 access token is used as a bearer token to authenticate the DSP when calling the DCP APIs.
The oAuth 2.0 access token will expire after 2 hours after the token is granted.
Once expired, a status code 401 is returned when calling a DCP API.
You should implement an automated process to generate a new token every 90 minutes using the refresh token.
Refresh Token
When you receive the refresh token, save it in the dealer's profile and reuse it to get the access token.
Once the access token has expired, the DSP can use the refresh token and call the Dealer Account Management service to get a new access token.
The received oAuth 2.0 token is used as a bearer token to authenticate the DSP when calling the DCP APIs.
The refresh token remains valid until it is revoked and must be reused for each refresh call.
You need to save the refresh token locally; it will not be returned during each refresh call.
The access token must be refreshed before it expires.
Even if the access token has expired, the refresh token stays valid!

The access token is dealer-specific!
One important aspect of Dealer Authentication is that the access token is specific to the dealer number used to get the authorization code.
If you obtain an authorization code for dealer 0000694650 and call a DCP API to perform an operation for dealer 0000691730, you will receive a status code 403 Forbidden.