Agricultural machines sending authenticated field-operation data through secure cloud processing into validated spatial datasets

Production System

John Deere Data Integration Platform

Layered System View

From Approved Access to Analytics-Ready Spatial Data

The integration moves through five connected layers—from secure customer authorization and organization verification to continuous token health, field-data acquisition and validated delivery.

  1. 01 Connect & Approve

    OAuth + PKCE

  2. 02 Verify Organization

    Scoped Access

  3. 03 Renew Continuously

    Token Health

  4. 04 Acquire Field Data

    Fields · Operations

  5. 05 Validate & Deliver

    Analytics-Ready

APPROVED ACCESS → ANALYTICS-READY SPATIAL DATA

Context

Problem & Responsibility

Operational Problem

Customer field and operation data required a slow, multi-step onboarding process before it was ready for analysis.

My Responsibility

Primary implementer and John Deere technical contact, responsible for integration design, ingestion, validation and operational recovery.

System Design

Architecture & Workflow

  1. 01

    John Deere APIs and OAuth/OIDC token lifecycle

  2. 02

    Webhook-triggered Cloud Run processing

  3. 03

    Automated shapefile download, cleaning and BigQuery loading

  4. 04

    Operational notifications, validation and recovery workflows

  5. 05

    Workload-aware processing: standard datasets stay on a simple Python path, with a Spark path for very large ones

  6. 06

    Harvest, planting and fertilizer-application data, each with crop-specific cleaning and standardization

Deep Dive

Inside the Build

Approach

Primary implementer and John Deere technical contact. Owned the technical John Deere API integration end to end: discovery and vendor due diligence, customer authorization, webhook-driven production processing, validation, standardization, cloud processing, failure reporting and delivery of analysis-ready data to BigQuery and downstream applications.

  1. 01

    Acted as the primary technical bridge to John Deere Operations Center/support, translating API capabilities and requirements into an implementation plan.

  2. 02

    Implemented customer authorization/authentication, persisted token information, and gated event-driven processing on access-permission checks.

  3. 03

    Used John Deere webhooks to detect new operational data, call the right endpoints, download and validate geospatial data, and load standardized output into BigQuery.

  4. 04

    Added failure reporting so analysts and account managers can see validation or processing issues without manually monitoring every ingestion.

  5. 05

    Designed workload-aware processing: a standard Python path for smaller datasets, and a Spark-based path above roughly 500,000 records.

  6. 06

    Processed multiple operation types (harvest, planting/seeding, fertilizer/application) with crop-specific cleaning and standardization.

Operational Architecture

From One Click to Analytics-Ready Field Data

The integration separates secure customer approval, credential renewal, data acquisition and delivery, so each stage can be monitored and recovered on its own.

  1. 01

    Access

    Connect & Approve

    A customer clicks Connect on John Deere’s own Connections page and approves their organizations there. No separate account is needed.

    • One-Time Approval
    • OAuth + PKCE
  2. 02

    Verification

    Verify & Store

    The one-time code is exchanged for tokens, real organization access is verified, and only working connections are saved for each organization.

    • Signed State
    • Per-Org Tokens
    • Audit Trail
  3. 03

    Continuity

    Renew Automatically

    A scheduled worker refreshes each 12-hour access token before it expires and alerts the team if a connection fails or is revoked.

    • Cloud Scheduler
    • Cloud Run
    • Alerts
  4. 04

    Acquisition

    Pull Field Data

    Organization-aware sessions fetch fields, boundaries and field operations, then request and download John Deere’s shapefile exports.

    • Fields
    • Boundaries
    • Operations
    • Shapefiles
  5. 05

    Delivery

    Clean & Load

    Exports are organized, cleaned and validated, then loaded into BigQuery, with notifications and recovery workflows around every run.

    • Validation
    • BigQuery
    • Notifications

Shared Controls

  • Per-Organization Isolation

    Every connection is stored against its own organization and never mixed with another.

  • Health & Audit Trail

    Active or revoked status and renewal history support troubleshooting.

  • Team Alerts

    Renewal failures and revoked access surface before data pulls are affected.

Interactive Diagrams

Explore the Full Architecture

Two views of the same integration: the secure access lifecycle, from the customer’s first click to automatic renewal, and the data pipeline that turns an approved connection into analytics-ready datasets. Drag to pan, use Ctrl or ⌘ with scroll to zoom, or expand the viewer to full window.

John Deere Connection — Secure Access LifecycleOne Customer Approval · Automatic Renewal · Organization-Specific Data Access
Customer Entry
Cloud Run — Connect
John Deere Approval
Cloud Run — Callback
Secure Connection Store
Existing JD API Scripts
Automatic Renewal
Connection Health & Support
Click ConnectStart ApprovalApproval CodeSave ConnectionLoad Org TokenScheduled CheckRefresh AccessSave Fresh Access TokenTrack StatusAlert On Failure
John Deere Customer
Operations Center
Finds The Integration Card
Clicks Connect
No Separate Account Needed
/connect
Start Secure Connection
Create State + PKCE Challenge
Send Customer To John Deere
Request Approved Data Scope
John Deere Sign-In
Approval Stays Inside John Deere
Customer Signs In
Chooses Organizations
Approves Data And Permissions
Returns One-Time Code
/callback
Complete And Verify Connection
Validate State + PKCE
Exchange Code For Tokens
Verify Real Organization Access
Accept Only Working Connections
Managed Database
One Record Per Organization
Connections Table
Organization + Scope
Access + Refresh Tokens
Expiry + Active Status
Activity History
Connected / Reconnected
Renewal Failures
JD API Scripts
Organization-Aware Sessions
Look Up Correct Organization
Open Secure API Session
Pull Field Data
Pull Harvest Data
Pull Boundaries
Cloud Scheduler
Runs Before 12-Hour Expiry
Renewal Worker
Cloud Run Background Process
Find Tokens Near Expiry
Use Long-Term Renewal Key
Save Fresh Access Token
John Deere Token Service
New 12-Hour Access Token · Same Refresh Token
Connection Health
Active / Revoked Status
Renewal History
Support Trail
Team Alerts
Renewal Failed
Customer Revoked Access
Connection Needs Attention
Confirmed Connection Facts
PKCE SupportedState and verifier protect the approval handoff.
12-Hour Access TokensRenewed automatically before they expire.
Stable Refresh TokenConfirmed: the long-term renewal key does not rotate.
One-Time Customer SetupNo separate account or repeat approval required.

Architecture adapted from the operational integration. Environment-specific resource names, endpoints and credentials are intentionally omitted.

Evidence

Scale & Measurable Impact

  • Reduced data readiness from approximately one week to approximately one day
  • Demonstrated capacity of approximately 40,000 acres per day
  • Supported roughly 50 customers
  • Approximately 250,000 acres captured for the John Deere production workflow

Technologies

  • Python
  • Cloud Run
  • BigQuery
  • OAuth / OIDC
  • Webhooks
  • Spatial ETL

Let’s Connect Spatial Data to Real Decisions.

Open to conversations about geospatial engineering, cloud data platforms, GeoAI and spatial analytics.