How-toOracle Fusion Cloud ERPFusion REST APIs / Integration

Paginate And Authenticate Oracle Fusion REST API Calls Correctly

Question
How to paginate and authenticate Oracle Fusion REST API calls

Also searched as

  • Oracle Fusion REST API limit offset pagination
  • Oracle Fusion REST API basic auth
  • Fusion REST API hasMore totalResults
  • Oracle ERP Cloud REST API authentication

Short answer

Oracle Fusion Cloud REST APIs authenticate with HTTP Basic Authentication, an integration user's credentials, over HTTPS by default, and paginate with limit and offset query parameters rather than a page number. Loop on the hasMore flag in the response until it returns false to retrieve a full result set.

Applies to: Oracle Fusion Cloud ERP REST APIs (fscmRestApi), all current API versions

Call and paginate a Fusion REST resource correctly

  1. 1Create or reuse an integration user with a job or duty role that grants REST API access and the data security needed for the resource you are calling.
  2. 2Build the request against the resource URL and send the Authorization header as Basic base64(username:password) over HTTPS.
  3. 3Add onlyData=true to strip HATEOAS link noise from the payload if you only need the data attributes.
  4. 4Add limit and offset to control page size, starting with offset=0; the default limit is commonly 25 if you omit it, which silently truncates larger result sets.
  5. 5Read the hasMore field in the response body; if true, increment offset by your limit and repeat the call.
  6. 6Use totalResults=true only when you need an exact count, since computing it adds overhead to every call - avoid it on high-frequency polling.
  7. 7Prefer a q= filter or a finder to narrow results server-side instead of pulling every row and filtering client-side.
  8. 8Check the response's links array for an entry with rel next as an alternative to manually tracking offset yourself.

Why The Default Page Looks Incomplete

Integrations commonly lose records because the default limit, often 25, silently caps the response and the caller never checks hasMore. The API is not failing - it returned exactly what was asked for. Always check hasMore and loop rather than assuming a single call returns everything.

GET /fscmRestApi/resources/11.13.18.05/purchaseOrders?limit=100&offset=0&onlyData=true
Authorization: Basic base64(username:password)

Authentication Options

HTTP Basic Authentication over HTTPS with a dedicated integration user is the default and most common pattern for Fusion ERP REST APIs. Some tenants also support federated SSO or OAuth-based flows depending on how Identity Cloud or OCI IAM is configured, but Basic Auth against a tightly scoped integration user remains the simplest, most widely used setup for server-to-server integrations.

Security Roles Behind The API

The integration user needs both function security, a role that includes the REST resource's function privilege, and data security, a data role or security profile scoping which business units, ledgers, or cost organizations the user can see. A 403 response, or an empty result set with no error, is frequently a data security scope problem, not a broken query.

Filtering With q= And Finders

The q parameter accepts a query expression, such as a status equality filter, to filter server-side; finders are prebuilt, named queries some resources expose for common lookups. Both reduce payload size and the number of calls compared to pulling every record and filtering in your integration code.

Common pitfalls

  • !Hardcoding a single call with no pagination loop, so only the first page, often 25 rows, ever gets processed.
  • !Reusing a personal user's credentials for integrations instead of a dedicated integration user, which breaks when that person's password rotates or access changes.
  • !Requesting totalResults=true on every polling call, adding unnecessary load for a count you do not actually need each time.
  • !Assuming a 200 response with zero rows means no data exists, when it can also mean the data security profile hides those rows from the integration user.
  • !Not URL-encoding the q= filter expression, causing the query to silently fail or return unexpected results.
  • !Polling too frequently without checking rate limiting guidance, which can throttle or block the integration user.

How an ERP-grounded AI assistant handles this

For integration troubleshooting, ERPray can inspect an actual failed or truncated REST call against your Fusion tenant - the URL, headers, and response - and tell you directly whether it is a pagination gap, a missing data role, or a malformed q filter, instead of you working through the REST API guide error code by error code.

Frequently asked questions

What does hasMore actually mean?

It is a boolean in the response body indicating whether more records exist beyond the current page given your limit and offset. Treat it as the loop condition: keep calling with an incremented offset while hasMore is true, and stop once it returns false.

Does Oracle Fusion REST API support OAuth?

Some Fusion environments support OAuth or SSO-based authentication depending on how Identity Cloud or OCI IAM is configured for the tenant, but HTTP Basic Authentication with a dedicated integration user remains the standard, most commonly documented pattern for server-to-server REST integrations against Fusion ERP.

Why do I get 403 even though my credentials are correct?

Correct credentials only satisfy authentication. The integration user also needs a role with function security for that REST resource and a data role or security profile granting access to the specific business unit, ledger, or other scoped data you are requesting - missing either produces an access error even with valid login credentials.

How large can I set limit?

Oracle enforces a maximum page size per resource; requesting more than the maximum typically gets capped rather than rejected. For large extracts, it is usually more reliable to page in moderate batches, for example 100 to 500 rows, than to push for one enormous response.

Related

Error fix

Fix FBDI Import Failures From Interface Table Validation Errors

When a Fusion FBDI import job errors out, the cause is almost always bad data in the interface tables (an invalid value set, a wrong date format, or a missing required column), not the ESS job itself. Open the process's Interface Errors Report or the Correct Import Errors spreadsheet to see the exact rejected rows and reason codes, fix the source data, and resubmit from the interface tables instead of re-running the whole FBDI load.

Error fix

Fix The Oracle Fusion "You Don't Have Access To This Data" Error

This generic Oracle Fusion security message means the function privilege and the data security scope did not both line up for that user on that record - most often the job role is assigned but the matching data role, security profile, or business unit and ledger context in Manage Data Access for Users is missing. Fix it by checking data access setup for the user's role, not by re-granting the same job role again.

How-to

OTBI vs BI Publisher: Which One Should You Use

Use OTBI when a business user needs ad hoc, self-service, real-time analysis with no fixed layout. Use BI Publisher when you need a pixel-perfect, scheduled, high-volume, or externally distributed document such as an invoice, check, or statutory report. Most Fusion implementations end up using both, not one instead of the other.

Error fix

Clear An Oracle Fusion ESS Job Stuck In Blocked Status

A Blocked status on an Oracle Fusion Enterprise Scheduler (ESS) job almost always means an earlier instance of the exact same job is still running or stuck, and the job definition does not allow simultaneous requests. Find and finish, or cancel, the earlier request first; only then does the Blocked request move to Running.

How-to

HCM Data Loader Vs FBDI: Which One Loads Your Fusion Data

HCM Data Loader (HDL) is the dedicated bulk tool for HCM business objects - workers, assignments, compensation, absences - and uses a plain-text .dat file with METADATA and MERGE or DELETE action lines, not a spreadsheet template. FBDI is the general Financials and SCM bulk-load framework built on Excel macro templates that stage data into interface tables. If the object lives in HCM, use HDL; if it lives in Financials, Procurement, or SCM, use FBDI.

How-to

Connect Oracle Integration Cloud (OIC) To Fusion ERP

OIC connects to Fusion ERP primarily through the prebuilt ERP Cloud Adapter, which wraps Fusion's REST and SOAP web services with OAuth-based authentication and pick-list discovery of available business objects and operations, instead of you hand-building every REST call. Use the adapter for standard integrations; drop to a generic REST or SOAP adapter only when the ERP Cloud Adapter does not yet expose the specific service you need.

AI for ERP

Fusion Cloud ERP AI: OCI Generative AI Service vs. a Private LLM

Oracle's OCI Generative AI Service is a real option for Fusion Cloud ERP, but not the only one. Compare it honestly against a private LLM for sensitive data.

AI for ERP

Oracle ERP AI Consulting: What a Partner Should Deliver

What to demand from an Oracle ERP AI consulting partner across EBS, JD Edwards, NetSuite, and Fusion Cloud: interface tables, APIs, and buyer questions.

Stuck on Oracle Fusion Cloud ERP?

Talk to engineers who work inside Oracle Fusion Cloud ERP every week, and who build private AI that answers these questions from your own ERP data.