It includes an @Tenant suffix. The instance root, tenant, and connected application must match.
Before you start
- The Acumatica instance root, such as https://erp.example.com/AcumaticaERP.
- Access to Connected Applications (SM303010) in the target tenant.
1. Create a connected application
Create an active Authorization Code application in Connected Applications (SM303010).
Use a connected application in the Acumatica tenant you want to read. Its client ID, shared secret, and redirect URI must belong to the same application. The client ID includes the tenant after an @ sign, so copy the full value into Permute.
Choose Authorization Code in Connected Applications (SM303010). Add Permute’s OAuth callback URI to that application. A different URI will stop authorization before Permute can connect.
- Keep the application active.
- Copy the secret when you generate it and store it securely.
- If you use several tenants, check the tenant suffix before authorizing.
2. Set the redirect URI and secret
Add https://api.permute.ai/oauth/callback under Redirect URIs and generate a shared secret. For other Permute environments, use the callback URL shown on the setup screen.
3. Set token and data access
Use Sliding Expiration for refresh tokens. Grant only the access needed for read-only reporting.
The application authorizes access through an Acumatica user. That user must be able to see the OData records Permute needs. If a customer, order, inventory, or financial record is missing, check the user’s access in Acumatica before changing the Permute connection.
Grant only the access needed for reporting. In Acumatica, set Sliding Expiration for refresh tokens as the setup screen instructs.
4. Add Acumatica in Permute
In your workspace, open Connectors, select Add Connector, choose Acumatica, and name the account.
Under Sync which data?, choose an option:
| Choice | What it does |
|---|---|
| Recommended | Selects core tables. |
| Select manually | Choose the tables Permute syncs after connecting. |
Connection details
| Field or access | What to use |
|---|---|
| Instance URL | The root URL of the Acumatica instance, including its application path. |
| OAuth Client ID | The ID from Connected Applications, including @Tenant. |
| OAuth Client Secret | The shared secret from that application. |
- Enter the Instance URL, OAuth Client ID, and OAuth Client Secret. The client ID includes an @Tenant suffix.
- Select Connect to authorize the application.
5. Choose tables (manual selection)
If you chose Select manually, open the connector after connecting. Use the checkboxes to select at least one table, then select Save selection.
6. Check the first result
- Choose a known customer or order in the intended Acumatica tenant.
- Confirm the authorizing user can see it, then compare the connected data and selected table.
Available data
| Data group | What the setup screen covers |
|---|---|
| Customers and orders | Customer and order records available through the connected OData account. |
| Inventory and finance | Inventory and financial records available through that account. |
Understand Acumatica OData
Acumatica places the DAC endpoint under the instance and tenant: /t/<TenantName>/api/odata/dac. Its metadata lists DACs, fields, field types, and links to related DACs. The instance root and tenant suffix in the OAuth client ID are separate values to check during setup.
Read related fields carefully
Acumatica metadata describes links between DACs as navigation properties. For example, a sales order can link to order lines and to a customer account. An order header and its lines are distinct records; compare the same level of detail on both sides of a report.
If a field is missing from a DAC-based OData result, inspect that tenant’s DAC metadata and the user’s access. The field may belong to a related DAC. Use the metadata field names rather than assuming that an Acumatica screen label is also the OData field name.
Access and source details
Check the instance address
Permute asks for the instance root, such as https://erp.example.com/AcumaticaERP. Use the address of the instance that contains the chosen tenant. Do not paste a screen URL from inside Acumatica; the OAuth app and OData requests need the instance root.
If your company has test and live instances, prepare a connected application and credentials for the instance you select. Check the address, tenant suffix, and app together before retrying a failed connection.
Review refresh-token settings
The Permute setup screen calls for Sliding Expiration on refresh tokens. That setting lets the app renew access while the connection is used. If the connected application’s token policy or secret changes later, the saved authorization may need to be renewed.
When access stops, confirm the connected application is active before changing the Permute account name or table choice. Those choices do not repair a revoked application or invalid secret.
Troubleshooting
| Problem | What to check |
|---|---|
| Authorization stops | Check the instance root, callback URI, full client ID, secret, and application status. |
| Records are absent | Check the tenant, the authorizing user’s access, and the selected tables. |