Applyfin
Administration

API Tokens

The tokens that give an outside system access to your company.

An API token lets another system, such as an integration you built, access your company's data. Tokens are managed under Settings > API Tokens, and a token opens on General with its own Permissions.

A token belongs to a user or to an agent, but it has its own permissions, separate from the owner's role. So what the other system can access is decided on the token, not by who created it.

Relations

  • Company — a token gives access to one company.
  • User — a user has their own tokens, on their API Tokens tab.
  • Agent — an agent has its own tokens, on its API Tokens tab.

Creating a token

To give another system access to your company, create a token for it.

  1. Open Settings > API Tokens and select Create New.
  2. On Token Owner, pick User or Agent.
  3. Select Next.
  4. On Owner Selection, pick the user or the agent.
  5. Select Next.
  6. On General Settings, fill in the Name and a Description.
  7. Set the Expiration.
  8. Select Next.
  9. On Permissions, choose what the token may do.
  10. Select Create Token.

The token value is shown once, under API Token Created. Copy it, then select I've saved my token.

The token is shown only once. Applyfin cannot show it again. If you lose it, create a new one.
Expiration offers Tomorrow, In a week, In a month, In 3 months, In 6 months and In a year. Setting one is recommended.
If you create a token from a user's or an agent's own API Tokens tab, the first two steps are skipped, because the owner is already known.

Setting permissions

To limit what a token can access, set its permissions.

  1. Open Settings > API Tokens, select the token, then select Permissions.
  2. Turn off Full access.
  3. Turn on the scopes the token needs.
  4. Select Save Permissions and confirm the action.

The permissions are View Any, View, Create, Update, Assign and Delete.

Full access gives the token every permission. Leave it off unless the other system really needs all of them.

Rotating a token

To give a token a new value without changing anything else, rotate it.

  1. Open Settings > API Tokens, select the token, then select Danger Zone.
  2. Select Rotate Token.
  3. Confirm the action and select Rotate.

The new value is shown once. Copy it before you close the dialog.

The old value stops working immediately. Any system still using it breaks until you give it the new one.

Finding a token

The list shows the Name, the Status, the Owner, the Last Used, the Expires and the Created.

A token is Available or Expired.

To find one, open Settings > API Tokens, search by name, and filter on Expiration Status, Usage Status or Owned By.

Looking for the API reference? It is documented separately.
Copyright © 2026