# B2B Creds Validation — api.pharmalink.id
# Date: 2026-09-07

## Discovery

| Parameter | Value |
|-----------|-------|
| Frontend | scm.pharmalink.id (Next.js) |
| API | **api.pharmalink.id** |
| Auth | **Basic Auth** (username:password base64) |
| Endpoint | /auth/v2/login |

## Test Results

| Username | Password | Method | Result |
|----------|----------|--------|--------|
| APOTEK-BERKAT8 | berkat8 | JSON body | 401 NIP Not Found |
| Apotekaldan | Abcd1234 | JSON body | 401 NIP Not Found |
| APOTEK-BERKAT8 | berkat8 | Basic Auth | 401 NIP Not Found |
| Apotekaldan | Abcd1234 | Basic Auth | 401 NIP Not Found |

## Analysis

**"NIP Not Found"** — username is not recognized as NIP (Nomor Induk Pegawai = employee ID).

B2B creds from sendgrid are **NOT** for scm.pharmalink.id internal system. They are for:
- External B2B pharmacy portal
- Different system (not employee login)
- Possibly apotek*/klinik* external ordering system

## Conclusion

| Finding | Status |
|---------|--------|
| B2B creds valid for scm | ❌ NO — NIP not found |
| B2B creds for external portal | ✅ YES — different system |
| api.pharmalink.id requires | Internal employee NIP |

## Next Steps

1. **Find external B2B portal** — where these creds actually work
2. **Check other subdomains** — apotekcentury.id, etc.
3. **Password reuse** — try on other services
