Get an API key
An administrator issues keys on the API keys screen. Every key belongs to an identity, which holds roles and site access the same way a person does. The key can never do more than its identity, so give the identity the roles your integration needs before you issue the key. The key is shown once, when it is issued. Store it the way you would store a password.Trade the key for a token
Callexchange_api_key with no token:
Keep the token fresh
A token from a key lasts fifteen minutes. Reuse it for all of them. Trading the key again on every request is refused as a rate limit. Before the token runs out, either trade the key again or callrefresh_session with the token you
have. Both answer with a new token.
Check who the token is
whoami returns the account the token belongs to, its roles and its organisation. It is the quickest
way to confirm a new key works.
Act on behalf of a person
If the identity is set to act as A person on the API keys screen, passp_on_behalf_of with that person’s email address. The token then names the person, so what your
integration writes is recorded against them. The token can do only what the person, the identity and
the key all allow.
Sign in with an email and password
A script that a person runs for themselves can sign in as that person instead of using a key:token that you use the same way. Prefer a key for anything that runs
unattended: a key does not stop working when a person leaves or changes their password.
A tenant on its own hostname uses that hostname in place of
app.assetinfinity.ai. Every example
on these pages uses https://app.assetinfinity.ai/api.
