> For the complete documentation index, see [llms.txt](https://help.ica.illumina.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.ica.illumina.com/get-started/gs-getstarted.md).

# Get Started

## Tenant-level setup

### Software Registration

If you are a new user, please consult the [Illumina BioInsight Platform Registration Guide](https://help.connected.illumina.com/account-management/rg-registration) for detailed guidance on setting up an account and registering a subscription.

### Tenant Setup

The platform requires a provisioned tenant in the[ **Illumina account management**](https://help.connected.illumina.com/account-management/admin-console) ([IAM](https://help.connected.illumina.com/account-management/admin-console)) system with access to the **Illumina BioInsight Platform Core** application. Once a tenant has been provisioned, a tenant administrator will be assigned. The **tenant administrator** has permission to manage account access including adding users, creating workgroups, and adding additional tenant administrators.

Each tenant is assigned a domain name used to login to the platform. The domain name is used in the login URL to navigate to the appropriate login page in a web browser. The login URL is `https://<domain_name>.login.illumina.com` with `<domain_name>` replaced by the actual domain name.

{% hint style="warning" %}
If you have intrusion detection systems active on your infrastructure, be aware that activities performed by Platform Core on your behalf (such as accessing [your own S3 storage](/home/h-storage/s-awss3.md) ) might trigger suspicious activity alerts. Please review the alerts and rules with your vendor to set up appropriate policies on your detection system.
{% endhint %}

* by the **tenant administrator** by logging in to their domain and navigating to **Illumina Account Management** under their profile at the top right
* or by the **user** by accessing `https://platform.login.illumina.com` and selecting the option **Don't have an account**.

Once the account has been added to the domain, the tenant administrator may assign registered users to [workgroups](https://help.connected.illumina.com/account-management/admin-console/workgroups) which bundle users with permission to use the Platform Core application. Registered users can be made workgroup administrators by tenant administrators or existing workgroup administrators.

***

## Access via Web UI

The web application provides a visual user interface (UI) for navigating resources in the platform, managing projects, and extended features beyond the API. To access the web application, navigate to the [Illumina BioInsight Platform Core portal](https://ica.illumina.com/ica).

* On the **left**, you have the **navigation bar** (1) which will auto-collapse on smaller screens. To collapse it, use the **double arrow symbol** (2). When collapsed, use the >> symbol to expand it.
* The **central** **part** (3) of the display is the item on which you are **performing your actions** and the **breadcrumb** **menu** (4) to return to the projects overview or a previous level. You can also use your browser's back button to return to the level from which you came.
* At the top **right**, you have icons to **refresh contents** (5) I**llumina product access** (6), access to the **online help** (7) and **user** **information** (8).

<figure><img src="https://3193631692-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MWUqIqZhOK_i4HqCUpT%2Fuploads%2Fgit-blob-f328cce8859c66085a517faa746c1230fda5cfd3%2Fimage%20(142).png?alt=media" alt=""><figcaption></figcaption></figure>

* When **left clicking**, the popup will let you refresh the screen or go back to the previous screen.

<div align="left"><figure><img src="https://3193631692-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MWUqIqZhOK_i4HqCUpT%2Fuploads%2Fgit-blob-706f577044408a1e53a7831ef5aabf770b7326ab%2Fimage%20(169).png?alt=media" alt="" width="145"><figcaption></figcaption></figure></div>

## Access via the API

The HTTP-based application programming interfaces (APIs) are listed in the [Swagger API Reference](https://ica.illumina.com/ica/api/swagger/index.html) which shows detailed information about the API schemas. There you will also find the option to call APIs from the browser page to test what each API call does. Alternatively, HTTP client tooling such as Postman or cURL can be used to make direct calls to the API outside of the browser.

**To get the Swagger API reference page to work** with your Platform Core instance, you need to authenticate the API calls by means of an **authorization token** (JSON Web Token). This is a standardized trusted token containing authentication context. This mechanism helps prevent unauthorized access to projects, analyses, pipelines, and data across ICA accounts. A JWT is generated by providing user credentials (API Key or username/password) to the token creation endpoint.

* **API key** (ApiKeyAuth) is the simplest credential type. This is a long-lived key which is used to obtain a JSON Web Token. API Keys operate similar to a user name and password combination and must be **kept secure** and **rotated on a regular basis.** You can have **up to 10 API keys per user** and manage them through the product dashboard after logging in through the [domain login URL](https://ilmn.login.illumina.com/platform-home/#/home). See[ Managing API Keys](https://help.connected.illumina.com/account-management/platform-home#manage-api-keys) for more information.
* **Username and password** (basicAuth) can be used for the POST tokens endpoint to exchange your user credentials for a JWT token. If you use this method, the credentials are sent to the token-generating endpoint which will return a JSON Web Token the returned JWT Token should then be used for subsequent API calls.
* The **JWT bearer token** (JwtAuth) is the preferred authentication method. The JWT **will expire** after a pre-configured period specified by a tenant administrator through the IAM console in the Illumina portal. If the token was generated by using a username and password then it **can be refreshed** using the POST /tokens:refresh endpoint as long as it has not expired.
* **Appt-to-app tokens** (PsTokenAuth) are only supported by the /data:transferOwnership endpoint

#### API Key Security

{% hint style="warning" %}
Once the API key generation window is closed, the key contents will not be accessible through the domain login page, so be sure to store it securely for future reference.
{% endhint %}

{% hint style="warning" %}
For security reasons, **never use accounts with administrator level access** to generate API keys. Create a specific CLI user with basic permissions instead. This will minimize the possible impact of compromised keys.
{% endhint %}

{% hint style="danger" %}
When **keys are compromised or no longer in use, they must be revoked**. This is done through the [domain login URL](https://ilmn.login.illumina.com/platform-home/#/home) by navigating to the User menu item on the left and selecting "API Keys", followed by selecting the key and using the trash icon next to it.
{% endhint %}

#### Object Identifiers

The object data models for resources that are created in the platform include a unique `id` field for identifying the resource. These fixed machine-readable IDs are used for accessing and modifying the resource through the API or CLI, even if the resource name changes.

## Access via the CLI

The command-line interface offers a developer-oriented experience for interacting with the APIs to manage resources and launch analysis workflows. Find instructions for using the command-line interface including download links for your operating system in the [CLI documentation](/command-line-interface/cli-installation.md).

***


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://help.ica.illumina.com/get-started/gs-getstarted.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
