Creating API account
Related Articles
- Introduction to Fleet Complete API
- API User management
- API calls generic description
- API Customer management
- Vehicle management
- System callbacks
- Creating API account
- API Tasks management
- Vehicle bookings management
If you get request to create API user, this article covers, what to do and consider when doing it.
Who can get API key
First check, who is that person, who is asking API user.
Sales
If they are from FC+ Sales as customer representative, you have green light for making API user.
Outside FC+ organisation
Search their e-mail from Reseller/admin.
If you don't find this user, then ask, what organisation he represents and what user does he use for logging into our service. Request for API user should come from existing FC+ user. If they don't tell you, deny their request, because it's security concern, you cannot give access to our system from someone, who doesn't should have permission for it.
If you find that person, then check their roles. Request for doing API user should come to end-user, who has administrator rights in FC+, or any Sales person (aka customer representative from FC+ side). If any end-user with reduced rights asks for it, you should tell, that you need confirmation from any administrator in his organisation, and deny their request, if they refuse.
Creating API user
API user is like any other user, except it has API key field filled. But because of it's usually used for third-party service, giving it out should be secure. So API user must have as few permissions as possible and as much as minimally needed.
- Create API role
Open customer organisation in Reseller/Admin, and navigate to Roles. Create API role, and give permission only to Vehicles module. Customer can add permissions to API role later, but they cannot access to API key.
-
Create API user
-
Open People tab in Reseller/Admin, and create new user.
- e-mail: api-companyname@ecofleet.com (we don't want to create API user with customer domain like api@companyname.com), because password e-mails are sent to that address, and it's security concern too, but we will use any Fleet Complete domain, like fleetcomplete.eu, ecofleet.com etc)
- check is user
- give it only API role
- fill API key
- save
- re-check, did that API key really got only API role (sometimes, default roles are added too)
API key
There is no clear rule, what API key should look like, it may be any text, but there are some unwritten recommendations:
- start with api-
- follow with company name with lowercase letters
- add random text. For example, use password generator here, and create at least 16 digit hash. Recommended settings are: use only numbers and letters, not symbols.
Example
If your company is, for example, Microsoft, your API key might look like this:
api-microsoft-xp4KB87d3eZqfamU