Skip to content

API & Integrations

API & Integrations is how other systems are let in, deliberately: keys issued and revoked, integrations managed in one place, and 2,644 routes available to a caller who is authorised for them.

Try it in the demoapikeys · 3 tasks

Before you start

  • A named owner per key. A key nobody owns is a key nobody revokes.
  • A decision about what each integration is allowed to reach — an API key inherits permissions, it does not escape them.

What API & Integrations does

Letting other systems in, deliberately.

01

Issue and revoke keys

Issue one key per system rather than one shared key, so revoking one integration does not break four.

02

Manage integrations in one place

One register of what is connected. The alternative is finding out during an incident.

03

Use the routes

The 2,644 routes are the same ones the application uses, so anything the interface can do is reachable to an authorised caller.

Worth knowing

  • Revoke a key the day the integration is retired. Unused keys are the ones nobody notices being used.

What it claims to do

The capability list this guide is written against, unabridged. Nothing above adds to it.

API & Integrations on the Administration page
  • Keys issued and revoked
  • Integrations managed in one place
  • 2,644 routes available to authorised callers

Where it connects

The modules API & Integrations hands work to, or takes it from. Most problems that look like one module are a handover between two.