Authentication
All CSL SIM Insight API requests must be authenticated.
Authentication ensures that:
- Requests are associated with a valid account
- Permissions are enforced
- All activity is logged securely
Unauthenticated requests are not processed.
Authentication Model
Each API request must include valid account credentials.
These credentials:
- Identify your account
- Authorise the requested action
- Control the scope of permitted operations
Authentication details are included as part of every request.
Requests submitted without valid credentials will be rejected.
Account Scope
Authentication is account-bound.
This means:
- Requests can only act on SIMs and groups associated with your account
- Permissions reflect your account configuration
- Access cannot extend beyond authorised scope
If your account is restricted to specific SIM types, groups, or customers, API access will follow the same restrictions.
Security Responsibilities
API credentials must:
- Be stored securely
- Be protected from unauthorised access
- Not be embedded in client-side applications
Credentials should only be used within secure server-side systems.
Because API commands can perform immediate operational changes, safeguarding credentials is critical.
Failed Authentication
If authentication fails:
- The request will not be processed
- An error response will be returned
Integrating systems must detect and handle authentication failures appropriately.