Create an API client
Only the company’s owner and admins can create API clients.1
Go to API clients
Open Settings → API clients in Envoi and choose Create API client.
2
Choose a type
Accounting client comes set up with access to invoices, customers, journal entries and reports. Advanced setup lets you choose the environment and exactly which permissions the client gets.
3
Copy the secret
The secret is shown once, and Envoi does not store it. Copy it right away and keep it safe. You also need the client ID and account ID.
Get a token
The response:
Use the token
Permissions
Permissions are written asresource:level, for example invoices:write. Levels build on each other: admin includes write, and write includes read.
If the client lacks the permission an endpoint needs, you get
403 insufficient_scope.
Changes apply immediately
Envoi checks the client against the database on every call, not just the token:- Delete the client, and its tokens are refused on the next call.
- Rotate the secret, and tokens issued with the old one are refused on the next call.
- Remove a permission or an environment, and it applies from the next call.
Token endpoint errors
The token endpoint answers with{ "error": "<code>" }, as OAuth 2.0 describes.