This standalone release lets clients with Integration API access manage up to 10 named API keys and keep multiple integrations connected at the same time.
This release adds a self-service Integration API page to Client Settings, where Admins can manage up to 10 named API keys and turn on Use modern authentication. Previously, each Portal had a single API key, and each new authentication canceled the previously issued access token, so two integrations could not reliably run at the same time. With Use modern authentication turned on, several access tokens stay valid at once, even when integrations share one key.
Who's affected: Clients who already have Integration API access enabled. This release does not enable Integration API access for any additional Portals.
Default state: Use modern authentication is off by default. Your existing API key continues to work, and additional keys are optional.
Admin control: System Admins manage both capabilities Portal wide from Client Settings > Integration API.
Use modern authentication has no grace period. It takes effect on the next API request, and any integration that is not already sending Authorization: Bearer <token> stops working immediately. This change is made inside each integration, not in Absorb. If you are building your first integration, this does not apply to you: turn the setting on first and build with the Bearer scheme from the start.
This release introduces three connected capabilities for clients with Integration API access: a self-service Integration API page, support for multiple API keys, and the Use modern authentication setting.
Integration API Page in Client Settings
A new Integration API card in Client Settings opens a self-service page for managing API keys and authentication settings, with no support ticket required. The card appears only for Portals that already have Integration API access enabled. To open the page, follow these steps:
- In the Admin Experience (AE), click your Account icon in the top-right corner of the page.
- Click Client Settings.
- Click the Integration API card.
Multiple API Keys
Admins can now create up to 10 API keys per Portal, including the default key, so each integration can have its own labeled credential. Each key has the following properties:
- Name: Required, up to 255 characters.
- Description: Optional, up to 1,000 characters.
- Key: Generated automatically when you click Save. The value is read-only.
Keys can be renamed or deleted from the Actions column without affecting any other key. The original default key can be renamed but not deleted, so integrations that still depend on it keep working. When a Portal reaches the 10-key limit, the Add API key button is disabled.
Use Modern Authentication
The new Use modern authentication setting lets multiple integrations authenticate and stay connected at the same time, instead of each new login canceling the previous one. It works with your existing single API key, so creating additional keys is not required. Once the setting is on, every Integration API request must send its access token using the Bearer scheme: Authorization: Bearer <token>.
Creating additional API keys does not, by itself, stop integrations from logging each other out. Use modern authentication must be turned on to keep multiple access tokens valid at the same time.
Before You Turn On Use Modern Authentication
How you prepare depends on whether integrations are already calling the Integration API for your Portal. If you have integrations already running, work with whoever maintains each one and complete these steps in order:
- List every integration that authenticates against the Integration API.
- Confirm that each integration sends its access token as
Authorization: Bearer <token>. - Have any integration that does not use this format updated, in its code or in the connection settings of the tool that calls Absorb.
- Verify each updated integration.
- Turn on Use modern authentication and confirm the dialog.
If no integration is calling the Integration API yet, there is nothing to migrate. Turn on Use modern authentication first, and then build your integration to use the Bearer scheme from the start.
The setting is reversible. If an integration stops working, turn Use modern authentication off to restore access immediately. No confirmation is required, and access tokens already issued continue to work until they expire, up to 4 hours. Update the integration, and then turn the setting back on.
For full setup steps, troubleshooting, and frequently asked questions, see Integration API Keys and Modern Authentication.
For more information about Client Settings, see The Client Settings Page.
Comments
Article is closed for comments.