Authentication

An API key and password combination will be provided for each jeweler using an integrated system. The APIs use the key and password as basic authentication inputs. Based on the API key used, the JM® Care Plan system will be able to determine which jeweler to associate a given call with. Should an integrated system manage more than one JM Care Plan jeweler via these APIs, they will need to ensure the right API key is used for a given API call.

API keys should not be stored in the front end client code. All calls to the JM Care Plan APIs must come from a backend service to ensure the API key and password are kept secure.