Edmissa docs

API Access

Manage API tokens used by trusted external tools and integrations.

API Access lets admins create and manage API tokens for trusted external tools. Use it when a connected tool needs controlled access to Edmissa data or actions.

Treat API tokens like passwords. A token can allow another system to act inside the workspace based on the access granted to it.

What this guide helps you configure

AreaWhat it helps with
Token creationGenerate a token for a trusted integration or internal tool.
Token namingMake each token easy to identify later.
Access reviewConfirm who owns the token and why it exists.
Rotation and removalReplace or revoke tokens when access should change.

Before you start

Prepare these decisions before generating a token:

ItemWhy it matters
Integration ownerOne person should own the token and know why it exists.
Use caseThe token should have a clear job, such as a website form, reporting tool, or approved integration.
Access needGive only the access needed for that job.
Storage planDecide where the token will be stored securely after it is generated.
Review dateTokens should be reviewed on a schedule.

Do not generate tokens for casual testing unless you know how they will be removed after the test.

Open API Access

Use this path when you want to manage API tokens:

  1. Open Settings.
  2. Open API Access.
  3. Confirm the page title is API Access.

The direct route is /t/settings/api-access.

Use Generate Token when a trusted external tool needs a new token.

Generate a token

Use this flow when a new token is needed:

  1. Open API Access.
  2. Select Generate Token.
  3. Add a clear name for the token.
  4. Choose the access settings shown in your workspace.
  5. Generate the token.
  6. Store the token in the approved secure location.
  7. Record who owns it and what it is used for.

Only share the token with the person or system that needs it. If a token is copied into an unsafe place, revoke it and create a new one.

Naming guidance

Use token names that explain the owner and purpose.

Better nameWhy it works
Website Lead FormShows the token belongs to the website intake flow.
Reporting Export ToolShows the token belongs to reporting work.
Approved Partner IntegrationShows the token belongs to a partner connection.

Avoid names such as test, new token, or a person's first name only. Those names become difficult to review later.

Safe API Access practices

PracticeWhy it matters
Use one token per systemIf one system changes, you can revoke only that token.
Keep access narrowA token should only do the work it needs to do.
Store tokens securelyTokens should not be kept in chat messages, spreadsheets, or plain notes.
Review tokens regularlyOld tokens can keep access open after a project ends.
Revoke unused tokensRemove access when a tool, partner, or test is no longer active.

If you are not sure whether an external tool needs API access, pause and review the integration plan first.

Test after setup

After generating a token:

  1. Confirm the token name is clear.
  2. Confirm the token owner is documented.
  3. Test the connected tool with sample work.
  4. Confirm the tool can do only the intended job.
  5. Review audit logs or activity history when available.
  6. Revoke the token if the test is no longer needed.
GuideUse it for
Security and auditReview how API access fits with account protection and audit review.
IntegrationsConnect external tools and Lead channels.
Lead SourcesTrack which channels create Leads.
Audit LogsReview activity after sensitive changes or connected-tool activity.
Permissions and scopeUnderstand access levels and system setting access.