API access
Create API tokens for integrations, choose what each token can do and how long it lasts, and revoke tokens you no longer need.
Last updated
The API Access settings page is where account administrators create the tokens that let other systems read and update your AssetCenter data through the AssetCenter API — a reporting tool pulling asset counts every month, a script that creates people from your HR system, or a service desk that looks up who holds a laptop.
Open Settings from the main menu, then API Access. Only account administrators see it.
This page covers creating and managing tokens. For the endpoints themselves, request and response formats and code examples, see the API guide, starting with the quick start.
Create a token
- Enter a Token name that says what the token is for, such as Monthly reporting or HR sync. You will see this name in the token list, so make it clear enough to know what breaks if the token is revoked.
- Choose when it Expires after: 30 days, 90 days or 1 year. A token stops working when it expires, and you create a new one to replace it.
- Choose its Permissions (see below).
- Press Create token.
The new token is shown only once. Copy it into your integration's secret storage, then press I've saved it. AssetCenter does not keep a readable copy, so if it is lost, revoke it and create another.
Permissions
Give each integration only what it needs. There are three presets:
- Read Only — view organization settings, users, invitations, categories and their fields, assets, people, locations, subscriptions and their timeline history. It does not include billing.
- Full Access — everything the API can do, including creating, updating and permanently deleting records, changing and deleting the organization, managing login settings, exporting data, inviting users and managing their access, managing categories and custom fields, and reading plan usage and invoices.
- Custom — choose each permission yourself, for each kind of record and for organization, user, billing, category and event settings.
A few actions need more than one permission. Decommissioning an asset needs the assets Manage lifecycle and Delete permissions; cancelling or retiring a subscription needs the subscriptions Manage lifecycle and Delete permissions. An assignment needs Manage assignments on the record being assigned and Update on the record it is assigned to. The page explains these rules next to the relevant permissions as you choose them.
A token's permissions cannot be changed after it is created. To give an integration more access, create a new token and revoke the old one.
Which organization a token works on
A token belongs to the organization it was created in and only ever works on that organization's data. Switching organizations in the app does not change what a token can reach, and a token cannot create or switch organizations.
A token works only while the administrator who created it can still create one. If that person is deactivated, removed from the organization, or is no longer an account administrator, their tokens stop working. When an administrator leaves, create replacement tokens under another administrator before removing them.
Managing tokens
The Organization tokens list shows every integration token in the organization: its name, who created it, when it was created, when it was last used and when it expires. Expired tokens are marked Expired.
Any account administrator can press Revoke on any token. Integrations using it lose access immediately. Revoke a token as soon as the integration using it is retired, or if you think it has been exposed.
The Last used time is a quick way to find tokens nothing is using any more.