When the API Digital Experiences Site is created, an API Guest user is automatically created. The API Guest user operates in the background, overriding traditional licensing and object-level and field-level security access to communicate with API partners to populate fields in the TMS.
Without an API Guest user, API integrations would need login credentials to process events via the QueuedTransactionJob and Platform Events to update fields in the TMS.
See the Digital Experiences Sites article for more information on creating Digital Experiences Sites.
Sharing Rules
Configure sharing rules by navigating to Setup → Security → Sharing Settings. The following sharing rules are set for API Guest users:
Object Name | Access Level |
|---|---|
Account | Read |
User | Read |
Accessorial | Read |
Carrier Markup | Read |
Carrier Markup Group | Read |
Commodity | Read |
Customer Invoice Document | Read |
Customer Quote | Read |
Document Options | Read |
Equipment Type | Read |
Freight Class Calculation | Read |
Freight Plan | Read |
Fuel Index | Read |
Lane | Read |
Load | Read |
Mode | Read |
Portal Configuration | Read |
TMS Document | Read |
Transportation Profile | Read |
Permission Set Access
The API Guest user operates like an unauthenticated user. The API Guest user is created after the creation of the API Digital Experiences Site and is assigned to the TMS API Community permission set on the User record.
Note: The API Guest user and the API Site user are not the same and do not share the same permission sets. The API Guest user operates as an unauthenticated user; whereas, the API Site user is an authenticated and credentialed user specifically for API integrations.
See the Email Loop Setup article for information on configuring the API Guest access.
TMS API Community Permission Set
The TMS API Community Permission Set allows the API Guest user limited Read and Create permissions to process data from transactions and payloads that match fields populated in the TMS.
Change or create custom permissions for TMS-specific objects and fields based on business needs.
Object Permissions
Warning: Because these permissions are provided for external access, take caution when editing object permissions to ensure sensitive data is not compromised.
By default, the API Guest user can broadly Read and Create the following objects:
Queued Transactions
The API Guest user cannot Edit, Delete, View, or Modify objects for Performance IQ and Queued Transactions.
These object permissions can be edited to allow additional API Guest user permissions on other objects by navigating to Setup → Users → Permission Sets → TMS API Community → View Summary.
Field Permissions
The default field permissions for PerformanceIQ and Queued Transactions are as follows:
Object Name | Field Label | Read Access? | Edit Access? |
|---|---|---|---|
Configuration State | Y | N | |
Data Storage and Data Storage Max | Y | N | |
File Storage and File Storage Max | Y | N | |
Error Detail | Y | Y | |
Payload 1 | Y | Y | |
Payload 2 | Y | Y | |
Request IP Address | Y | Y |