# Authentication

Required credential parameters sent with every gateway request, and how to verify them with the TESTAUTH action.

Source: https://developer.inoviopay.com/api/authentication.html  
Markdown: https://developer.inoviopay.com/api/authentication.md

Authentication parameters are required on every request to the gateway. You can use the `TESTAUTH` action to verify your credentials are functioning correctly.

| Parameter | Description |
|---|---|
| `REQ_USERNAME` (required) | Merchant's Service username. |
| `REQ_PASSWORD` (required) | Merchant's Service password. |
| `SITE_ID` (required) | Merchant's website ID. |
| `REQUEST_API_VERSION` (required) | Must be sent as `4.14` on all requests. |
| `REQUEST_RESPONSE_FORMAT` (optional) | Format of the response. Accepts `XML` (default), `JSON`, or `PIPES`. |

**cURL**

```bash
curl -X POST "https://api.inoviopay.com/payment/pmt_service.cfm" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "request_action=TESTAUTH&req_username=api_user&req_password=P%40ssw0rd%21&site_id=12345&request_api_version=4.14&request_response_format=JSON"
```

**PHP**

```php
use Inovio\Gateway\{Credentials, InovioClient};
use Inovio\Gateway\Errors\AuthenticationException;

$client = new InovioClient(new Credentials('api_user', 'P@ssw0rd!', '12345'), 'SANDBOX');

try {
    $health = $client->testAuth();
    echo $health->ok, "\n";
    echo $health->outcome->service->code, ' ', $health->outcome->service->advice, "\n";
} catch (AuthenticationException $e) {
    // Bad credentials raise an exception (API tier 101), never a decline.
    echo 'rejected: ', $e->getMessage(), "\n";
}
```

**Node**

```ts
import { InovioClient, AuthenticationError } from '@inovio/gateway-sdk';

const client = new InovioClient(
  { reqUsername: 'api_user', reqPassword: 'P@ssw0rd!', siteId: '12345' },
  { environment: 'SANDBOX' }
);

try {
  const health = await client.testAuth();
  console.log(health.ok);
  console.log(health.outcome.service.code, health.outcome.service.advice);
} catch (e) {
  // Bad credentials raise an error (API tier 101), never a decline.
  if (e instanceof AuthenticationError) console.log('rejected:', e.message);
  else throw e;
}
```

**Python**

```python
from inovio_gateway import AuthenticationError, Credentials, InovioClient

client = InovioClient(Credentials("api_user", "P@ssw0rd!", "12345"), environment="SANDBOX")

try:
    health = client.test_auth()
    print(health.ok)
    print(health.outcome.service.code, health.outcome.service.advice)
except AuthenticationError as e:
    # Bad credentials raise an exception (API tier 101), never a decline.
    print("rejected:", e.message)
```

**Java**

```java
import com.inoviopay.gateway.errors.AuthenticationException;

InovioClient client = new InovioClient(
    new InovioClient.Credentials("api_user", "P@ssw0rd!", "12345"));

try {
    HealthResult health = client.testAuth();
    System.out.println(health.ok());
    System.out.println(health.outcome().service().code() + " " + health.outcome().service().advice());
} catch (AuthenticationException e) {
    // Bad credentials raise an exception (API tier 101), never a decline.
    System.out.println("rejected: " + e.getMessage());
}
```

**Response**

```json
{
  "REQUEST_ACTION": "TESTAUTH",
  "TRANS_STATUS_NAME": "",
  "TRANS_VALUE": "",
  "TRANS_ID": "",
  "CUST_ID": "",
  "XTL_CUST_ID": "",
  "MERCH_ACCT_ID": "",
  "CARD_BRAND_NAME": "",
  "PMT_L4": "",
  "API_RESPONSE": "0",
  "API_ADVICE": " ",
  "SERVICE_RESPONSE": 100,
  "SERVICE_ADVICE": "User Authorized",
  "PROCESSOR_RESPONSE": 0,
  "PROCESSOR_ADVICE": " ",
  "INDUSTRY_RESPONSE": 0,
  "INDUSTRY_ADVICE": " ",
  "REF_FIELD": "",
  "PROC_NAME": "",
  "AVS_RESPONSE": "",
  "CVV_RESPONSE": "",
  "REQUEST_API_VERSION": "4.14",
  "TRANS_NTOKEN_USED": 0
}
```
