API tokens
API tokens are personal access keys that let integrations and scripts work with the system through its REST API, without signing in through the browser. Each token acts on your behalf, with your permissions.
Create a token when another system, such as an ERP or a reporting script, needs to read or update warehouse data automatically.
How to open API tokens
Section titled “How to open API tokens”- Click your name in the top bar.
- Click My profile.
- Select the API tokens tab.
The tab appears only if your role has the Use the API permission.
What’s on this screen
Section titled “What’s on this screen”- The form to create a token.
- Your tokens — every token you created, with its name, abilities, when it was created, when it was last used (or Never used), when it expires (or Never expires), and a Revoke button.
How to create a token
Section titled “How to create a token”- Enter a Token name that tells you where it is used.
- Under Abilities, tick Read, Write or both.
- In Expires after, choose how long the token stays valid.
- Enter Your current password.
- Click Create token.
- In Your new API token, click Copy and store the token in a safe place.
Fields
Section titled “Fields”- Token name — required, up to 100 characters.
- Abilities — at least one. Read lets the token view data. Write also lets it create and change records through the API.
- Expires after — 7, 30, 90, 180 or 365 days, or a default or no expiry, depending on the system settings. Longer periods than the system maximum are not offered.
- Your current password — required to confirm that it is really you.
How to revoke a token
Section titled “How to revoke a token”- In Your tokens, click Revoke next to the token.
- Confirm in the Revoke API token dialog.
Any integration using that token stops working immediately.
Who can do this
Section titled “Who can do this”You need the Use the API permission.