Skip to main content
Every request except the two that hand out tokens carries a session token. An integration gets its token from an API key. A script a person runs for themselves can sign in with an email and password instead.

Get an API key

An administrator issues keys on the API keys screen. Every key belongs to an identity, which holds roles and site access the same way a person does. The key can never do more than its identity, so give the identity the roles your integration needs before you issue the key. The key is shown once, when it is issued. Store it the way you would store a password.

Trade the key for a token

Call exchange_api_key with no token:
The answer is a list with one row:
Send the token as a bearer token on every other request:
A refused key still answers with HTTP 200. Check error_code before you use token: on a refusal token is null and message says why.

Keep the token fresh

A token from a key lasts fifteen minutes. Reuse it for all of them. Trading the key again on every request is refused as a rate limit. Before the token runs out, either trade the key again or call refresh_session with the token you have. Both answer with a new token.
A request with a missing, malformed or expired token is answered with HTTP 401.

Check who the token is

whoami returns the account the token belongs to, its roles and its organisation. It is the quickest way to confirm a new key works.

Act on behalf of a person

If the identity is set to act as A person on the API keys screen, pass p_on_behalf_of with that person’s email address. The token then names the person, so what your integration writes is recorded against them. The token can do only what the person, the identity and the key all allow.

Sign in with an email and password

A script that a person runs for themselves can sign in as that person instead of using a key:
The response carries a token that you use the same way. Prefer a key for anything that runs unattended: a key does not stop working when a person leaves or changes their password.
A tenant on its own hostname uses that hostname in place of app.assetinfinity.ai. Every example on these pages uses https://app.assetinfinity.ai/api.