Team, permissions & API

API keys and the API

Let another system read and write your IDup data, under a key you can revoke.

Last updated 22 September 2026 · More in Team, permissions & API

An API key is a password that belongs to a program instead of a person. Treat it the same way: issue one per system, and revoke it when that system goes away.

Where to find itAPI → API management.

Step by step

  1. Open API → API management and create a key.
  2. Give it a name that says which system uses it — future-you will need to know which one to revoke.
  3. Copy the key once. It is not shown again; if you lose it, issue a new one.
  4. Store it in the calling system's configuration, never in code you share or in a document.
  5. Read API → API guide for the endpoints and the request shapes.
  6. Revoke the key the day the system that used it is decommissioned.

The other interfaces

  • Customer API in the sidebar is the customer-facing interface, with its own settings page.
  • Automation / workflows → GraphQL → Token issues a GraphQL token and links the documentation.
  • Automation / workflows → Webhooks pushes events out instead of being polled — see Webhooks and connecting other systems.
  • AI Studio → Personal API keys is a separate set, for the AI Studio side.

Keeping it safe

  1. One key per system, never a shared one.
  2. Give a key only the access the system needs.
  3. Rotate keys on a schedule, and immediately when somebody who knew one leaves.
  4. Watch Central → Audit log for what a key did.
Was this article helpful?

Nothing is tracked — the buttons only open a message so you can tell us what was missing.

Related articles

idup

All-in-One Accounting, Payroll & Digital Finance — Simplified

Copyright © 2026 - IDup. All rights Reserved.