> ## Documentation Index
> Fetch the complete documentation index at: https://docs.connectedfleet.michelin.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

## OAuth2 Bearer Token Authentication

The APIs require an OAuth2 access token. Follow the steps below to obtain a token and use it in your requests.

### Prerequisites

Contact your account manager to obtain:

* **Client ID** (`clientId`)
* **Client Secret** (`clientSecret`)

### Step 1: Generate an OAuth2 Access Token

Make a POST request to the OAuth2 token endpoint.

**Endpoint:**

```
POST https://auth.masternautconnect.com/masternauth-oauth/oauth/accessToken
```

**HTTP Headers:**

| Header          | Value                                | Description                                      |
| --------------- | ------------------------------------ | ------------------------------------------------ |
| `Authorization` | `Basic <base64-encoded-credentials>` | Your clientId and clientSecret encoded in Base64 |
| `Content-Type`  | `application/x-www-form-urlencoded`  | Required to pass the `grant_type`                |

**Create the Authorization Header:**

Combine your `clientId` and `clientSecret` with a colon separator and encode in Base64:

```bash theme={null}
echo -n "clientId:clientSecret" | base64
```

Example result: `Y2xpZW50SWQ6Y2xpZW50U2VjcmV0`

**Request Body:**

```json theme={null}
{
  "grant_type": "client_credentials"
}
```

**Example Request:**

```bash theme={null}
curl --location 'https://auth.masternautconnect.com/masternauth-oauth/oauth/accessToken' \
  --header 'Accept: application/json' \
  --header 'Content-Type: application/x-www-form-urlencoded' \
  --header 'Authorization: Basic Y2xpZW50SWQ6Y2xpZW50U2VjcmV0' \
  --data-urlencode 'grant_type=client_credentials'
```

**Response:**

```json theme={null}
{
  "success": true,
  "accessToken": "B983854936PF1A7B61B141AB69494046",
  "token_type": "bearer",
  "expires_in": 2591999
}
```

| Field         | Description                                              |
| ------------- | -------------------------------------------------------- |
| `success`     | `true` if authentication was successful                  |
| `accessToken` | The OAuth access token to use in subsequent API requests |
| `token_type`  | The token type, will always be `bearer`                  |
| `expires_in`  | Token lifetime in seconds                                |

### Step 2: Use the Access Token

#### Standard Bearer Token

Include the access token in the `Authorization` header using the Bearer scheme.

**Example Request:**

```bash theme={null}
curl --request GET \
  --url https://api.masternautconnect.com/connect-webservices/services/public/v1/customer/{customerId}/tire/events \
  --header 'Authorization: Bearer B983854936PF1A7B61B141AB69494046' \
  --header 'Content-Type: application/json'
```

**Required Headers:**

| Header          | Value                        | Description                       |
| --------------- | ---------------------------- | --------------------------------- |
| `Authorization` | `Bearer <your-access-token>` | Your OAuth2 bearer token          |
| `Content-Type`  | `application/json`           | Required for requests with a body |

***

## Token Management Best Practices

* **Token Expiration:** OAuth tokens have a limited lifetime. Implement token refresh logic in your application.
* **Secure Storage:** Store client credentials and tokens securely using environment variables or secret management systems.
* **Error Handling:** Implement proper error handling for authentication failures and token expiration scenarios.
* **Token Reuse:** Cache and reuse valid tokens across multiple requests to minimize authentication overhead.

***
