> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cloud.cdata.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> All requests to the Connect AI API must be properly authenticated using either Basic Authentication or OAuth 2.0 Client Credentials.

## Basic Authentication

To authenticate a request using Basic Authentication, pass the Base64-encoded login credentials of a registered user in the `Authorization` header of the request. Follow this guidance when passing the credentials:

* The username is the email address of the user, e.g. `user@cdata.com`.
* The password is a Personal Access Token (PAT) that you generate from the [Settings](/en/Settings#personal-access-tokens) page.
* If your application or service does not automatically Base64-encode the string, follow these steps to encode it manually:
  * Separate the username and PAT with a colon, for example, `user@cdata.com:token`.
  * Use Base64 to encode the colon-separated string.

The following is an example of a curl command that calls the API to return results from a Salesforce Account table:

```bash theme={null}
curl -X POST https://cloud.cdata.com/api/query
   -H "Content-Type: application/json"
   -d '{"query":"SELECT * FROM Salesforce1.Salesforce.Account LIMIT 10"}'
   --user "user@cdata.com:123456789abcdefghijklmnopqrstuvwxyz"
```

Since curl automatically Base64-encodes basic authentication credentials, it is not necessary to manually perform this encoding before sending the request.

## OAuth 2.0 Client Credentials

Service accounts authenticate via the OAuth 2.0 Client Credentials flow. Use this method to authenticate scripts, jobs, and external services without a human user. You must first create a service account and copy its **Client Id** and **Client Secret** from the [Users](/en/Users#service-accounts) page.

**Step 1: Request a bearer token**

```bash theme={null}
curl -X POST https://cloud-login.cdata.com/oauth/token \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "grant_type=client_credentials&client_id=<ClientId>&client_secret=<ClientSecret>"
```

The response includes an `access_token` value.

**Step 2: Call the Connect AI API**

Pass the token as a Bearer credential in subsequent requests. For example, to run a query:

```bash theme={null}
curl -X POST https://cloud.cdata.com/api/query \
  -H "Authorization: Bearer <access_token>" \
  -H "Content-Type: application/json" \
  -d '{"query":"SELECT * FROM Salesforce1.Salesforce.Account LIMIT 10"}'
```

For integrations that prompt for OAuth configuration fields (such as Databricks MCP Marketplace), use the following values:

| Field                 | Value                                                                                  |
| :-------------------- | :------------------------------------------------------------------------------------- |
| **Token URL**         | [https://cloud-login.cdata.com/oauth/token](https://cloud-login.cdata.com/oauth/token) |
| **Authorization URL** | [https://cloud-login.cdata.com/authorize](https://cloud-login.cdata.com/authorize)     |
| **Client Id**         | The Client Id from the service account                                                 |
| **Client Secret**     | The Client Secret from the service account                                             |
