Connected apps and API tokens¶
Another program can work with your tracker as you: a browser extension, a script that files a backup, a tool that reads the log. Instead of your password it uses an API token.
The SUFS Tracker browser extension, set to On a tracker server in its options, uses a token to send the SUFS reimbursement requests it reads to your default account, and to fill the portal's form from that account's expenses. The SUFS requests page explains both.
Create a token¶
In Rules & settings → Sharing, under Connected apps, give the token a name that says what will use it (for example Laptop extension) and click Create token. The token is shown once; copy it into the program that needs it.
A token has the same rights as your login, in every account you belong to, and it doesn't expire. Treat it like a password: anyone holding it can read and change your accounts, and even create more tokens.
See and revoke tokens¶
The same section lists your tokens with when they were created and last used. Revoke stops one immediately; the program using it will be asked for a new one. If a token may have leaked, revoke it; there is no need to change your password, since the token never contained it.
For the program's author¶
Send the token in an Authorization: Bearer sufs_… header to the HTTP API; the first call to make is GET /api/me, which lists the user's accounts.