Skip to main content
The myConnectedFleet platform provides two authentication methods depending on the API you are using. This guide covers how to authenticate with each method.

1. Core API — Basic Authentication

This authentication method applies to the Vehicle Tracking API, Fleet Management, Performance API.
The Vehicle Tracking API, Fleet Management API, Performance API use HTTP Basic Authentication. Include your credentials directly in the Authorization header of every request.

Prerequisites

Contact your account manager to obtain:
  • Username (clientId)
  • Client Secret (clientSecret)

Create the Authorization Header

Combine your clientId and clientSecret with a colon separator and encode in Base64:
Example result: Y2xpZW50SWQ6Y2xpZW50U2VjcmV0

Example Request

Required Headers

Keep your Client ID and Client Secret secure. Never expose them in client-side code or public repositories.

2. Other APIs — OAuth2 Bearer Token Authentication

This authentication method applies to the following APIs:
These APIs require an OAuth2 access token. Follow the steps below to obtain a token and use it in your requests.

Prerequisites

Contact your account manager to obtain:
  • Client ID (clientId)
  • Client Secret (clientSecret)

Step 1: Generate an OAuth2 Access Token

Make a POST request to the OAuth2 token endpoint. Endpoint:
HTTP Headers: Create the Authorization Header: Combine your clientId and clientSecret with a colon separator and encode in Base64:
Example result: Y2xpZW50SWQ6Y2xpZW50U2VjcmV0 Request Body:
Example Request:
Response:

Step 2: Use the Access Token

Standard Bearer Token (Smart Tire, Tacho, Vehicle Check APIs)

Include the access token in the Authorization header using the Bearer scheme. Example Request:
Required Headers:

Custom Header (Job Management API)

The Job Management API uses a custom header instead of the standard Authorization header. Example Request:
Required Headers:
Note the TOKEN prefix before the access token value. This is required for the Job Management API.
Keep your Client ID, Client Secret, and access tokens secure. Never expose them in client-side code or public repositories.

Token Management Best Practices

  • Token Expiration: OAuth tokens have a limited lifetime. Implement token refresh logic in your application.
  • Secure Storage: Store client credentials and tokens securely using environment variables or secret management systems.
  • Error Handling: Implement proper error handling for authentication failures and token expiration scenarios.
  • Token Reuse: Cache and reuse valid tokens across multiple requests to minimize authentication overhead.