NERIS API Authentication + Authorization Guidance #18
Replies: 5 comments 2 replies
|
I would appreciate Oauth2 flows when you can. |
|
We are an RMS with two fire departments in the first set of ~100 departments selected for onboarding to NERIS. Will they be able to use our software connected to the API to enter their reports, or will they need to use the Survey 123-based ESRI system? |
|
Could you provide us with an estimated date when it will be possible to create incidents on behalf of multiple entities? Would the rest of the endpoints also be available for testing? If so, do you have a tentative date for their availability? The answer to this question would help us plan the transition of our RMS to NERIS and make design decisions. For example, as part of the testing we are running, we would like to have the possibility to create units so that we can later link them to the unit response payload (unit_neris_id) during incident creation. |
|
For our RMS, it would also be very convenient to have the OAuth2 flow available in the test environment. |
|
Update on Oauth2 and integration accounts here |
Uh oh!
There was an error while loading. Please reload this page.
Hello everyone,
In response to some questions we've been getting, we wanted to provide some guidance on authenticating to our AWS Cognito user pool in order to get the access token required to make authenticated requests to the NERIS API.
Authenticating to an AWS Cognito user pool
The most straightforward way to authenticate is using one of the many AWS SDKs available, or with the AWS CLI, using the InitateAuth API. To see how we authenticate you can have a look at our public NERIS API Client repo. The NERIS API Client we've published is also available as a PyPi package if you'd like to use that or to use it as an example.
NERIS API user pool config
There are a few values you'll need in order to complete
InitiateAuthsuccessfully. First, the auth flow that we're using isUSER_PASSWORD_AUTH(REFRESH_TOKEN_AUTHandUSER_SRP_AUTHare also allowed). The user pool ID and client ID are published at the publicly accessible URL https://neris-test-public.s3.us-east-2.amazonaws.com/cognito_config.json. This configuration information, along with your username and password, will be all that's necessary to generate an access token.NOTE If there is a need to use Oauth2 flows, please let us know and we can look into either adding those to the existing user pool client or creating a new one expressly for that purpose.
NOTE If using our published API client, be sure to set
env="test"at instantiation.Authorization
For this initial test window, we have given you access to both read entity information and create (and validate) incidents for the FSRI Fire Department entity. The NERIS ID for that entity is
FD24027214. As testing progresses we will be opening this up to allow a more realistic scenario where vendors will be able to create incidents on behalf of multiple entities.All reactions