API credentials

For a script or service of your own: it acts as you, only in this account, and only as far as you choose.

Step by step

  1. Open “Integrations”. The account’s owner sees this page.
  2. In the “Client credentials” card, choose “Create a credential” and give it a name you will recognise later.
  3. Under “Access”, pick how far it reaches: “Everything its creator may”, “Sales documents” (contacts, the company registers, the VAT ID validations, documents with their payments, PDF, ISDOC and sending, and the sales totals; no settings, bank accounts, people or integrations) or “Read only”.
  4. Choose “Create”. “Keep the secret now” shows the client ID and the client secret.
  5. Copy the secret to where your script reads it and choose “Done”. It is not shown again.
  6. With the client ID and the secret, the script asks /oauth/token for a token (grant client_credentials) and calls the API with it.
  7. “API use this month” counts the requests and says how many a minute each credential may make.
  8. Two switches under each credential and each OAuth application, both off until the owner turns them on: with “Every document it creates takes the VAT by the customer”, the VAT rates it sends are not used and each document’s VAT follows where its customer is and whether it is a business; with “No payment reminders to customers on its documents”, its documents get no reminder, neither automatic nor sent by hand.

Good to know

A credential acts within your role in the account. When your role changes, so does what it may do.

Choosing “Remove” at a credential stops its tokens at once.

Tento článek česky