Skip to main content

Extreme Reach — Authentication

B
Written by Ben Keeling

How to obtain dedicated Extreme Reach API credentials, connect them securely to Medialake, and limit access to the creative assets you want to synchronise.



What to expect

The Extreme Reach connection uses server-to-server API authentication. There is no browser consent screen: Medialake signs in to the Extreme Reach API with an API username and password, then uses the authenticated session returned by Extreme Reach to synchronise authorised creative assets and metadata.

Extreme Reach provisions API access for each customer. You cannot create the required credentials from Medialake, and they may not be available as a self-service option in your Extreme Reach account.

For the safest setup, ask Extreme Reach for a dedicated API account for Medialake with read-only access to only the customers, advertisers, brands, or asset catalogues that need to be synchronised. Do not use an employee's personal Extreme Reach login unless Extreme Reach specifically confirms that this is required for your account.


Before you begin

You will need:

  • An active Extreme Reach account containing the assets you want to synchronise

  • An Extreme Reach Client Manager, account representative, or support contact who can provision API access

  • Permission to create integration settings in Medialake; this normally requires a Medialake site administrator

  • A secure password manager or secrets-management system in which to store the API credentials

Decide which Extreme Reach customer accounts, advertisers, brands, or catalogues are in scope before requesting access.


Step 1: Request dedicated API credentials from Extreme Reach

Contact your Extreme Reach Client Manager or account representative and request credentials for a server-to-server Medialake integration.

You can use this wording:

> Please create a dedicated API account for our Medialake integration. It needs read-only access to list and search the creative assets in the agreed customer accounts, retrieve their metadata and available previews, and download the source media selected for synchronisation. It does not need permission to upload, modify, approve, deliver, or delete assets, or to change campaigns. Please provide the API username, API password, correct production API environment, and any customer or account identifiers required for the connection.

Ask Extreme Reach to confirm:

  • The API username and API password

  • That API access is enabled for the account

  • Which Extreme Reach customers, advertisers, brands, or catalogues the account can access

  • The correct production API environment for your organisation

  • Whether the credentials expire or must be rotated on a schedule

>Keep the password private. The person administering the connection should enter it directly into Medialake or share it through an approved secrets-management system. Do not send it through ordinary email or chat, paste it into a support ticket, or commit it to source control.


Step 2: Check the access boundary

Before adding the credentials to Medialake, confirm that the API account can see only the content required for the integration.

The Extreme Reach API includes both read and write operations. Medialake's asset synchronisation does not require campaign-management, upload, delivery, update, or deletion access. The permissions on the dedicated API account are therefore an important part of keeping the connection read-only.

If different business units must remain separate, request separate API accounts or credential sets from Extreme Reach and create a separate Medialake integration setting for each one.


Step 3: Add the credentials to Medialake

  1. Sign in to Medialake as a site administrator.

  2. Open Administration → Integrations.

  3. Select Extreme Reach.

  4. Open the Settings tab and select Create New Setting.

  5. Enter a clear title, such as Extreme Reach — UK Production.

  6. Enter the API username and API password supplied by Extreme Reach.

  7. If Medialake asks for an API environment, account ID, or customer ID, enter the production value supplied by Extreme Reach. Do not use the public developer environment unless Medialake Support has asked you to create a test connection.

  8. Save the setting and run the connection test if one is shown.

Medialake stores saved integration-setting values in encrypted form. Administrators should still treat the credentials as secrets and limit who can view or replace the setting.


Step 4: Connect the Extreme Reach source

  1. Open the team that should own the Extreme Reach connection.

  2. Add a connection and choose Extreme Reach from the integration catalogue.

  3. Select the integration setting created in the previous step.

  4. Complete the connection test.

  5. Select the available account, catalogue, or content scope you want to synchronise.

  6. Start with a small set of assets, then widen the synchronisation after verification.

The connection inherits the access granted to the Extreme Reach API account. Selecting a narrower source in Medialake controls what is synchronised, but the API account's permissions determine what the connection is capable of seeing.


Step 5: Verify the connection

After connecting, confirm that Medialake can:

  • Display the intended Extreme Reach account or content scope

  • List a recently added creative asset

  • Read the asset's name, identifier, status, and other expected metadata

  • Retrieve a thumbnail or preview when Extreme Reach makes one available

  • Download and synchronise one test asset

Also confirm that out-of-scope customer accounts, advertisers, brands, or catalogues are not visible. If they are, ask Extreme Reach to narrow the API account's access before enabling a full synchronisation.


Credential rotation and revocation

If Extreme Reach rotates or resets the API password:

  1. Update the existing Extreme Reach integration setting in Medialake.

  2. Test the new credentials.

  3. Confirm that an asset can still be listed and downloaded.

  4. Revoke the old credential only after the new one is working.

To remove access completely, disable the Extreme Reach source in Medialake and ask Extreme Reach to deactivate the dedicated API account or reset its password. Removing only the Medialake source does not deactivate the credential in Extreme Reach.


Troubleshooting

Symptom

What to check

Invalid credentials or 401 Unauthorized

Re-enter the API username and password exactly as supplied. Confirm that this is an API-enabled account, not an ordinary portal login, and check whether the password has expired or been reset.

403 Forbidden or an authorization error

Ask Extreme Reach to confirm that the API account has read access to the required customer, advertiser, brand, catalogue, asset metadata, and media resources.

The test succeeds but no assets appear

Confirm that the correct customer or account scope was selected and that the API account can see the assets in Extreme Reach. Check any date, status, or catalogue filters on the Medialake source.

Metadata appears but previews or files do not

Confirm that the API account can retrieve asset resources and that the asset has completed Extreme Reach processing. Some assets may not yet have a preview or downloadable resource.

The connection uses the wrong data

Check that the Medialake setting contains the production environment and customer or account identifier supplied for this organisation.

The connection stopped after a password change

Update the saved Medialake integration setting with the new password, then test the source again.

If the issue continues, contact [email protected] with the Medialake environment URL, integration-setting title, Extreme Reach customer or account ID, approximate time of the error, and the error message. Do not include the API password, session token, or downloaded media in the support request.


Further reading


Questions about connecting Extreme Reach? Contact [email protected] or your Extreme Reach Client Manager.

Did this answer your question?