API Keys
Mint the credential your own systems use to reach Trabalance. One key covers the REST API, webhooks and the MCP server — and it can never do more than the person who created it.
Navigate to: Settings → Connected apps → API keys
An API key is how something that is not a person signs in to your business — a warehouse script, an automation platform, an AI assistant. One key works across all three doors: the REST API, webhooks, and the MCP server that assistants connect through. Only the Super Administrator can see or create keys.
Creating a Key
The form opens on the same page.
Required. "Warehouse sync", "Zapier" — a name you will recognise in six months when you are deciding whether it is still needed.
Never, 30 days, 90 days, or 1 year. A key for a one-off migration should expire; a key running a permanent integration usually should not.
One row per feature, with four verbs: read, create, update, delete. Tick only what the integration actually needs. At least one scope is required.
The Allow AI assistants (MCP) switch lets an assistant use this key through the MCP server. The assistant is held to exactly the scopes above — it is not a separate permission set.
The full key is shown once, on creation, and is never displayed again.
Trabalance never stores your key in readable form, so it cannot show it to you a second time or email it to you. Put it straight into the system that needs it. If you lose it, revoke that key and create a new one — there is no recovery path, by design.
Scopes
Scopes are the app's own features, offered as the intersection of the full catalogue and what you personally hold. You cannot grant a key a right you do not have yourself, and the server re-checks those rights on every single call — so if the person who minted a key is later demoted, the key loses that access immediately rather than at its expiry date.
| Verb | What it allows |
|---|---|
| read | Fetch records for that feature. |
| create | Create new records. Turning this on turns read on with it. |
| update | Change existing records. Turning this on turns read on with it. |
| delete | Delete or void records. Turning this on turns read on with it. |
A write verb always brings read with it: a key that can create an invoice but cannot read the invoice it just created is a trap, not a policy.
Grant the narrowest set that works. A stock-sync job usually needs read on items and nothing else. A key that can delete should be rare and short-lived.
The Key List
| Column | What It Shows |
|---|---|
| Name | What you called it, with the first few characters of the key beneath — enough to identify it, never enough to use it. |
| Scopes | The features and verbs granted, as a compact list. |
| Created | The exact date and time the key was minted. |
| Expires | The expiry date, or Never. |
| Status | Active or Revoked. |
Revoking
Revoke stops a key immediately. There is no undo and no un-revoke: create a new key for anything that still needs access. Revoked keys stay in the list so the record of what existed is not lost.
Revoke a key when the integration is retired, when you suspect the value has leaked, or when the person who created it leaves. Revoking is cheap; leaving a live key attached to a system nobody owns is not.
Related
- Integrations — connections Trabalance builds and manages for you
- Team management — who holds Super Administrator
- Activity logs — the record of who created and revoked keys