Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

OAuth2 Configuration

2ea94d46a4f1a45d2d47d043
ItemValue
Token URLhttps://login.microsoftonline.com/6073ce8bf90faace-73f3b48d-4df44a19-9b80a39c-5e40cdc6965f1dd7b37686e3/oauth2/v2.0/token
Client ID1f018c75

11a51e47-

cee5-

4bb6-

882b-

a669dfaf1cb8

Client SecretYOUR_CLIENT_SECRET
Grant Typeclient_credentials
Scopeapi://4dad5d62e85dc5b1-dc8cf01b-437845bd-8bd0b48d-ae736a4d73fe08f50ee2e160/.default
Content-Typeapplication/x-www-form-urlencoded

Token Request

POST https://login.microsoftonline.com/6073ce8bf90faace-73f3b48d-4df44a19-9b80a39c-5e40cdc6965f1dd7b37686e3/oauth2/v2.0/token
Content-Type: application/x-www-form-urlencoded

grant_type=client_credentials
&client_id=1f018c7511a51e47-2ea9cee5-4d464bb6-a4f1882b-a45d2d47d043a669dfaf1cb8
&client_secret=YOUR_CLIENT_SECRET
&scope=api://4dad5d62e85dc5b1-dc8cf01b-437845bd-8bd0b48d-ae736a4d73fe08f50ee2e160/.default

Response:

{
  "token_type": "Bearer",
  "expires_in": 3599,
  "access_token": "eyJ0eXAiOiJKV1QiLCJhbGci..."
}

Token Lifetime: 1 hour


...

API Usage (

...

Prod Environment)

Base Configuration

ItemValue
API Base URLhttps://apiservice.gentledesertredbay-fcac7adc6992b142.swedencentral.azurecontainerapps.io/api/external
AuthenticationAuthorization: Bearer <token>
Content Typeapplication/json

...

  • Date range max 5 years
  • dateFrom must be ≤ dateTo

...

Configuration

Azure AD Setup

  1. Define API App Role

    Before external systems can be granted access, an App Role must be defined in the API App Registration.

    Go to:

    • Microsoft Entra IDApp registrations

    • Open EGU.PartnerPortal.ApiService

    Navigate to App roles → Create app role.

    Configure the role:

    FieldValue
    Display nameExternal System Access
    Allowed member typesApplications
    ValueExternalSystem.Access
    DescriptionAllows external systems to access turnaround report data

    Save the role.

  2. Create External System App Registration

    • Create a separate application registration for each external company.

      Go to:

      • Microsoft Entra IDApp registrations

      • Select New registration

      Configuration:

      SettingValue
      Name{CompanyName}-PartnerPortal-Access
      Supported account typesAccounts in this organizational directory only
      Redirect URILeave blank
  3. Generate Client Secret

      1. Open the newly created {CompanyName}-PartnerPortal-Access app.

      2. Navigate to Certificates & secrets.

      3. Click New client secret.

      4. Copy the secret value immediately and store it securely.

      ⚠️ The secret value cannot be viewed again after creation.

      Never commit secrets to source control.

  4. Assign Permissions

    • Add permission: EGU.PartnerPortal.ApiService
    • Select: ExternalSystem.Access
    • Grant admin consent

  5. Company Mapping (API side configuration)

    {
      "ExternalCompanies": {
        "Ravdex": {
          "AppId": "11a51e47-cee5-4bb6-882b-a669dfaf1cb8",
          "CompanyNumber": "YOUR_COMPANY_NUMBER",
          "Name": "Ravdex"
        }
      }
    }