Create your API key
Create in IAM the API key your integration uses to get tokens, one per environment.
An API key is your integration's credential: a client_id and a client_secret you exchange for an access token to call the Tax360 APIs. It is created and managed in IAM by your company's own user.
Sign in to see the IAM links for each environment.
Before you start
- You need a user from your company with access to IAM and permission to manage API keys. Access is created by support.
- One key per environment. A key created in UAT does not work in Production, and vice versa.
Create the key
- Open the IAM of the environment you want using the buttons above and go to API keys.
- Click create and fill in:
- Name: identifies the integration, for example
erp-billing. - Token validity: how long each token generated with this key is valid.
- Roles: the permissions the integration needs. Grant only what the operations it will call require.
- Name: identifies the integration, for example
- Copy the
client_idandclient_secretshown.
The secret is shown only once
Store the client_secret in a secrets vault right after creation. If it is lost or exposed, revoke the key in IAM and create another.
Use the key
Exchange the client_id and client_secret for a token with the client_credentials grant:
POST/api/integration/auth/tokenSign in to see the host and referenceThe step-by-step guide, with examples and token renewal, is in Authentication. Each environment's hosts are in Environments and hosts.
Good practices
- Use one key per integration and per environment, so you can revoke one without affecting the others.
- Never put the secret in source code, front-end code or repositories.
- Review roles when the integration changes and revoke keys that are no longer used.
Introduction
In this section you will find some general information about integrating with the Tax360 APIs, as well as some guides to common flows that will be…
Authentication and authorization
This guide shows how to authenticate requests to the Tax360 APIs and how to manage the lifecycle of the JWT token.