| Bookshelf Home | Contents | Index | PDF |    | 
| Oracle Web Services On Demand Guide > Establishing and Managing the Web Services Session > Using Stateful Web Services Requests > Oracle CRM On Demand Stateful Authentication MechanismsStateful login can be used with the Web Services v1.0, Web Services v2.0, Service, and Data Loader APIs, but is not available for the Administrative Services APIs. The following login options are supported by Oracle CRM On Demand for stateful requests: 
 Login Using HTTP GET (Providing UserName and Password in the HTTP Header)An HTTPS request can be used to instantiate an Oracle CRM On Demand Web services session and obtain a valid session ID. A client invokes login by sending an HTTP GET request to a URL such as the following: https://secure-ausomx[ENV].crmondemand.com/Services/Integration?command=login where [ENV] is the three-letter identifier for your company's environment. If you do not know what this value is for your company, refer to the URL you use to access the Oracle CRM On Demand UI. NOTE: The login parameter value is case sensitive. Login InputThere are different mechanisms for login depending on whether the login header contains URL encoding with the UTF-8 encoding system. This is necessary when login credentials contain multi-byte characters. The input to login is provided in the URL parameters and the HTTP headers, as follows: 
 Login OutputThe login command returns the following items: 
 For code samples for login, see: https://codesamples.samplecode.oracle.com/servlets/Scarab/action/ExecuteQuery?query=crm_on_demand Login with UserName and Password in the SOAP Security HeaderA similar login mechanism to that for stateless requests is used, but with a WSSE draft namespace (http://schemas.xmlsoap.org/ws/2002/04/secext or http://schemas.xmlsoap.org/ws/2002/07/secext) instead of the WSSE Version 1.0 Namespace. For more information, see Login with UserName and Password in the SOAP Security Header. The SOAP header contains the element <wsse:UsernameToken>, which has child elements containing a username and password: <wsse:Security soap:mustUnderstand="1"> <wsse:Username>USERNAME</wsse:Username> <wsse:Password Type="wsse:PasswordText">password</wsse:Password> NOTE: URL encoding of login credentials is not supported when they are provided in the SOAP security header. Login with Oracle CRM On Demand Single Sign-On (SSO) Token in the HTTP HeaderThis login mechanism is a type of outbound SSO, see Outbound SSO. The client instantiates an Oracle CRM On Demand Web services session and obtains a valid session ID by sending an HTTP GET request to the following URL and specifying the SSO token: https://secure-ausomx[ENV].crmondemand.com/Services/Integration?command=ssologin&odSsoToken=[SSOTOKEN] 
 If the login request is successful, the server returns the session ID in the response. The session will not be instantiated and the session ID will not be returned if the SSO token has expired. It is best practice to validate the SSO token before using it for login, see SSO Token Validation. SSO with SAML v1.1For SSO using Security Assertion Markup Language (SAML), Oracle CRM On Demand only supports the SAML Web Browser Profiles - the Browser/Artifact Profile and the Browser/POST Profile. For information about logging in and retrieving the session ID to be used for stateful requests, see Inbound SSO | 
|  |    | 
| Oracle Web Services On Demand Guide, Version 20.0 (Oracle CRM On Demand Release 32) | Copyright © 2016, Oracle and/or its affiliates. All rights reserved. Legal Notices. | |