Authentication


Eyelit MES offers integration with third-party applications through the use of a Public API. A series of endpoints are exposed and can be called by an external system (normally a middleware provider) to make changes directly within a given instance of the Eyelit software. The calls to these endpoints are done through the use of pre-formatted JSON packets and are authorised through OAuth 2.0.

The Eyelit MES-M Public API requires authentication to be accessed.

  • The method used by Eyelit MES is OAuth 2.0 – Password and Username. 
  • A call to [environment].mestec.net/Token is needed to create the authentication token. This token has a lifespan of 12 hours. 
  • The username and password required are that of an Eyelit user account within the target environment. 
  • This user account must be appropriately licensed and have the correct roles to carry out any transactions attempted by the endpoints. 
  • Management of this user account is the customer's responsibility. 

Request

             
MethodURL Structure
POST/Token

The following table lists all parameters and request body fields accepted by this endpoint.

                                                                                                       
NameLocation or TypeRequiredDescription
tenantQuery parameterYesThe unique identifier for the tenant environment against which authentication is performed. This value is supplied by Eyelit when your environment is provisioned.
grant_typeForm field (application/x-www-form-urlencoded)YesThe OAuth 2.0 grant type. Must be set to password for resource owner password credentials authentication.
usernameForm field (application/x-www-form-urlencoded)YesThe username of the Eyelit MES account for which the token is being requested.
passwordForm field (application/x-www-form-urlencoded)YesThe password associated with the specified username. Transmitted securely and never returned in any response.

Response

                                           
Status CodeDescription
200 OKAuthentication was successful. The response body contains the bearer access token, its type, and its expiry duration in seconds. Include the returned access_token value in the Authorization: Bearer header of all subsequent API calls.
400 Bad RequestThe request was malformed. This typically occurs when a required form field is missing, the grant_type value is not password, or the request body is not encoded as application/x-www-form-urlencoded.
401 UnauthorizedThe supplied username and password combination is invalid for the specified tenant, or the tenant identifier does not exist.
500 Internal Server ErrorAn unexpected error occurred on the server. If this error persists, contact Eyelit support with the request details and the time of the failure.
Knowledge Base Logo