> ## Documentation Index
> Fetch the complete documentation index at: https://docs.energy.nayax.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authenticate an asset using password authentication.

> Authenticates an asset using password authentication. If the asset is not configured to use password authentication, the password will be ignored. If the asset has an expired software license, the authentication request will be rejected.



## OpenAPI

````yaml /api/specs/assetManagement-api.json post /asset-management/v1/assets/basic-auth
openapi: 3.0.0
info:
  title: Lynkwell API
  version: 1.376.0
  description: API Documentation for assetManagement service
servers:
  - url: https://api.lynkwell.com
security: []
tags: []
paths:
  /asset-management/v1/assets/basic-auth:
    post:
      tags:
        - Assets
      summary: Authenticate an asset using password authentication.
      description: >-
        Authenticates an asset using password authentication. If the asset is
        not configured to use password authentication, the password will be
        ignored. If the asset has an expired software license, the
        authentication request will be rejected.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/BasicAuthReqBody'
      responses:
        '200':
          description: Success. Return station security profile if applicable.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecurityProfile'
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AssetManagementBadRequestError'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DefaultUnauthorizedError'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DefaultForbiddenError'
        '404':
          description: Not Found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AssetManagementNotFoundError'
        '409':
          description: Conflict
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AssetManagementConflictError'
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AssetManagementInternalServerError'
      security:
        - oauth2:
            - write:asset
components:
  schemas:
    BasicAuthReqBody:
      type: object
      required:
        - id
      properties:
        id:
          description: The id of the asset that is authenticating
          type: string
        password:
          description: >-
            Must be provided if the profile is PASSWORD. If the profile is
            INSECURE then it is optional and will be ignored
          type: string
    SecurityProfile:
      oneOf:
        - type: object
          required:
            - id
            - profile
            - createdAt
            - updatedAt
          description: >-
            Describe the security level of an asset. Status will only be present
            if the profile is PASSWORD
          properties:
            id:
              description: The id of the asset this security profile is associated with
              type: string
            profile:
              type: string
              enum:
                - INSECURE
            createdAt:
              type: string
              format: date-time
            updatedAt:
              type: string
              format: date-time
        - type: object
          required:
            - id
            - profile
            - createdAt
            - updatedAt
          description: >-
            Describe the security level of an asset. Status will only be present
            if the profile is PASSWORD
          properties:
            id:
              description: The id of the asset this security profile is associated with
              type: string
            profile:
              type: string
              enum:
                - PASSWORD
            status:
              type: string
              nullable: true
              enum:
                - REQUIRES_VERIFICATION
                - CONFIGURED
            createdAt:
              type: string
              format: date-time
            updatedAt:
              type: string
              format: date-time
    AssetManagementBadRequestError:
      type: object
      description: The response body for a 400 request
      properties:
        type:
          type: string
          enum:
            - BAD_REQUEST
        code:
          type: string
          enum:
            - INVALID_REQUEST_PARAMETERS
            - REFERENCE_ERROR
            - UNSUPPORTED_TYPE
            - LOCATION_VALIDATION_ERROR
            - CHARGING_STATION_VALIDATION_ERROR
            - SITE_HOST_VALIDATION_ERROR
            - UTILITY_VALIDATION_ERROR
            - UTILITY_USER_NOT_ALLOWED
            - INVALID_CONTACT_DETAILS
            - CONTACT_DETAILS_ALREADY_EXISTS
            - SITE_PARTNER_USER_ARCHIVED
            - ASSET_NOT_CONNECTED
            - LICENSE_ALREADY_ASSIGNED
            - INVALID_AUTH_METHOD
            - INVALID_ENROLLED_SERVICES
            - UNSUPPORTED_PAYMENT_TERMINAL_PROVIDER
            - UNSUPPORTED_SIM_PROVIDER
            - RATE_IN_USE
            - CHARGING_STATION_MODEL_ARCHIVED
            - OPERATING_SITE_HOST_NOT_FOUND
            - OPERATING_SITE_HOST_INVALID_TYPE
            - OPERATING_SITE_HOST_ARCHIVED
            - LOCATION_ARCHIVED
        message:
          type: string
    DefaultUnauthorizedError:
      type: object
      description: The response body for a 401 request
      properties:
        type:
          type: string
          enum:
            - UNAUTHORIZED
        code:
          type: string
          enum:
            - UNAUTHORIZED
        message:
          type: string
    DefaultForbiddenError:
      type: object
      description: The response body for a 403 request
      properties:
        message:
          type: string
    AssetManagementNotFoundError:
      type: object
      description: The response body for a 404 request
      properties:
        type:
          type: string
          enum:
            - NOT_FOUND
        code:
          type: string
          enum:
            - ASSET_NOT_FOUND
            - ASSET_STATUS_NOT_FOUND
            - ASSET_GROUP_NOT_FOUND
            - NETWORK_NOT_FOUND
            - FLEET_NOT_FOUND
            - SECURITY_PROFILE_NOT_FOUND
            - NETWORK_ACCESS_PROFILE_NOT_FOUND
            - SITE_PARTNER_NOT_FOUND
            - SITE_PARTNER_USER_NOT_FOUND
        message:
          type: string
    AssetManagementConflictError:
      type: object
      description: The response body for a 409 conflict request
      properties:
        type:
          type: string
          enum:
            - CONFLICT
        code:
          type: string
          enum:
            - CONFLICTING_SECURITY_PROFILE_STATE
            - CONFLICTING_SERIAL_NUMBER
            - CONFLICTING_CHARGING_STATION_MODEL
            - CONFLICTING_SHORT_CODE
            - CONFLICTING_PAYMENT_TERMINAL
            - CONFLICTING_NETWORK_ON_SIM_GROUP
            - ASSET_ARCHIVED
            - ACTIVE_CONNECTOR
            - ACTIVE_SESSION
            - LOCATION_ARCHIVED
            - LOCATION_HAS_ACTIVE_STATIONS
            - CONFLICT
        message:
          type: string
    AssetManagementInternalServerError:
      type: object
      description: The response body for a 500 request
      properties:
        type:
          type: string
          enum:
            - INTERNAL_ERROR
        code:
          type: string
          enum:
            - INTERNAL_SERVER_ERROR
        message:
          type: string
  securitySchemes:
    oauth2:
      type: oauth2
      description: OAuth2 Client Credentials Flow
      flows:
        clientCredentials:
          tokenUrl: https://lynkwell-prod.us.auth0.com/oauth/token
          scopes:
            read:asset: Retrieve assets
            write:asset: Create and update assets
            read:assetgroup: Retrieve asset groups
            write:assetgroup: Create and update asset groups
            read:assetstatus: Retrieve asset statuses
            read:chargingstationmodel: Retrieve charging station models
            write:chargingstationmodel: Create and update charging station models
            write:network: Create and update networks
            write:sitepartner: Create and update site partners
            read:sitepartner: Retrieve site partners
            write:sitepartneruser: Create and update site partner users
            read:sitepartneruser: Retrieve site partner users
            read:networkaccessprofile: Retrieve network access profiles
            write:paymentprofile: Create payment profile
            write:onboardinglink: Create an onboarding link
            read:invoice: Retrieve an invoice
            write:session: Create or update a session
            read:session: Retrieve a session
            write:ticket: Create a ticket
            write:verificationcode: Send and confirm verification codes
            write:driver: Create and update drivers
            read:driver: Retrieve drivers
            write:token: Create and update tokens
            read:token: Retrieve tokens
            read:tokenvalue: Retrieve token by ID including its value
            write:invitecode: Create and update invite codes
            write:invitation: Create and update invitations
            read:invitation: Retrieve invitations
            read:payment_terminals_payment: Read payments from payment terminal
            abort:session: Abruptly end session
            read:paymentprofile: Retrieve payment profile from payment terminal
            write:ocpp: Sends request over OCPP
            write:ocpp.raw_request: Sends raw request over OCPP
            write:notification.email: Create and update email
            read:invoiceitem: Retrieve invoice item
            read:subscription: Retrieve subscription
            write:plugandcharge_enrollment: Update Plug and Charge enrollment status
            write:projects: Create and update projects
            read:projects: Retrieve projects
            write:project_stations: Create and update project stations
            write:panel: Create and update panels.
            read:panel: Retrieve panels.
            write:webhooks: Create, update, and delete webhooks
            read:webhooks: Retrieve webhooks

````