API keys
Credentials for integrations — an ETL script, a print-farm manager — to call the API. Admins only.
Create: give it a name (who or what will hold it). The full key is shown once, on the page that follows; copy it then. Afterwards only its prefix is visible. A key works only on this company's subdomain.
Scope is a ceiling on the key, chosen when it is created and fixed after that:
| Scope | May |
|---|---|
read |
Look, never change |
write |
Everything operational: stock, work orders, tasks, drafts |
approve |
Also approve and send purchase orders |
Give a key the least it needs. A scope cannot raise anyone's role: an approve key acting for a planner still cannot approve. To change a key's scope, revoke it and create another.
Revoke disables a key immediately and permanently; the row stays so "which key did that" can always be answered.
Keys are sent as Authorization: Bearer fdr_….