Under Review. This workflow is under review, please do not implement it until this spoiler is removed. We apologize for the inconvenience.
Web Connections authorize ArcGIS Data Interoperability to work against ArcGIS Online services using the Esri ArcGIS Connector package, the Geocoder transformer, or other REST calls to the many services Online offers. Your authorization (permissions) for each of these services is tied to your Online account, but you must first authenticate who you are with Online.
There is a lot of confusion around the terms "authorize" and "authenticate". Strictly, authentication verifies an identity, while authorization determines what the identity is allowed to access with tokens granted by Online. The OAuth 2.0 protocol used is an authorization framework, user authentication is usually handled at the same time by sign-on layers like OpenID Connect. We don't need to go into these details further for the purposes of this blog.
We will cover the recommended way to configure Web Connections to Online, namely as app connections. This process has two steps:
- Create developer credentials in Online
- Create a web connection in ArcGIS Data Interoperability
Following the tutorial linked in step 1 above, also documented here, log into Online and navigate your Content in the home app to the folder you will use for the OAuth 2.0 credentials item. Use the New item control top left and choose to create a Developer credentials item.
Next, choose OAuth 2.0 credentials for app authentication.
Next, choose all owner privileges unless you have a reason to limit them.
Next, register http://localhost as the referrer.
Next, provide descriptive metadata.
Next, acknowledge the summary and security settings and Create the item.
You will then be taken to the new OAuth 2.0 credentials' item page. Click the Settings view. In the General view enter https://www.arcgis.com as the URL. This isn't used anywhere but a stable URL is required, I use https://www.arcgis.com. Next click Register Application.
Next, supply http://localhost as the redirect and referrer URLs and Register the item. The Application details will now display Client ID and Client Secret values, you need these for next steps so leave the item page open.
That completes making the credentials item, now we move to making the Web Connection in ArcGIS Data Interoperability. First make sure the Esri ArcGIS Connector package is installed and at the latest release. The simplest way is to download the package from the link above, open the Workbench app and from Windows Explorer drag the package file onto the canvas. Now in Workbench, from the Utilities > FME Options > Web Connections >Manage Services menu click the pulldown in the Add Web Service control and choose Create From the Esri ArcGIS Online OAuth (safe.esri-agol) template.
The Manage Web Services dialog will open, change the Web Service Name to something that makes it clear it's for Online, edit the Client ID and Client Secret to adopt the values from your recently created credentials item, set the Redirect URI to http://localhost and Redirect Strategy to Loopback Interface Redirect, and you are ready to Test the web connection!
Click on Test and you will be asked to allow the web service to access Online, click Allow.
Your browser will give you some encouragement…
Go back to Workbench and you'll be notified the web service was authorized successfully.
Dismiss this and you'll be rewarded with success!
Now the last step, creating your Web Connection from your Web Service. Go back to the Utilities > FME Options > Web Connections menu and click the Add Web Connection control bottom left (the big + symbol, Add option). Select to make it from your recently created Web Service.
You'll be asked to allow access once more and your Web Connection is ready to use!