## Setup
1. Install BGS Sample Backoffice.
2. In Service Center > Factory > Modules > BGSSampleBackoffice > Site Properties, set **DeviceApiKey** to a value of your choice (default: `demo-device-key`). The demo mobile app reads it through GetDeviceApiKey and sends it in the `X-Api-Key` header.
3. Note the API base URL; the demo mobile app needs it:
`https://<your environment>/BGSSampleBackoffice/rest/FieldAuditSync`
4. Open `https://<your environment>/BGSSampleBackoffice/` and sign in with any registered user.
Then install Background Sync Plugin with its demo (BGS Sample Mobile) and follow its setup.
## Check the API without the app (optional)
curl -X POST "https://<your environment>/BGSSampleBackoffice/rest/FieldAuditSync/photos" -H "Content-Type: application/json" -H "X-Api-Key: <DeviceApiKey>" -d '{"payload":{"auditKey":"AUD-TEST","auditTitle":"Test","site":"Lab","auditor":"Me","expectedPhotos":1,"findingKey":"F-01","findingTitle":"Test finding","severity":"minor","photoKey":"test-1","takenAt":"2026-10-07T10:00:00Z","sizeBytes":3},"file":{"filename":"test.jpg","contentType":"image/jpeg","base64Data":"AAEC"}}'
The audit `AUD-TEST` appears on the Audits screen with 1 photo. Sending the same request again counts it as re-sent; a wrong key returns an error.
## Notes
- The API key is a demo mechanism, not authentication. In a real app use per-user or per-device tokens (see docs/api-authentication.md in the repository).
- Base64 adds a third to the request size. Uploads above the IIS request limit (about 28 MB of body by default) need a higher limit or the plugin's PRESIGNED_URL strategy.
- The photo grid loads the full images; fine for a few dozen photos.