API Tokens

Magic Suite API Tokens are used both internally between each of our systems which access the Magic Suite REST API, for security and authentication purposes. They can also be created by Tenant Admins and assigned to users, as a way to directly query our API programmatically (such as using the Magic Suite API nuget package in C#), or via third-party application tools such as Postman.

Admins may create and manage API Tokens in the Admin App.

Users of any level may also view and manage their own API Tokens by clicking the Profile icon in any of the Magic Suite apps, and clicking the "My API Tokens" link.

Available from version 4.3: From the My API Tokens page, you can also regenerate the secret key for any of your own tokens. Select the token from the list and click the Regenerate Key button. You will be asked to confirm before the key is replaced - note that any integrations using the current key will stop working immediately. The new key is displayed once for you to copy and store securely, and cannot be retrieved again afterwards.

Older API tokens are being retired

Some older API tokens use a security scheme that Magic Suite is retiring. If you own one, or are a Tenant Administrator of a tenant that has one, you receive an email naming the tokens affected and the date they will stop working, followed by reminders a week and a day before that date.

To keep a token working, use it once before the date in the email. It is upgraded to the current scheme automatically, and nothing else changes: the same name and key keep working.

If you would rather not wait for the token to be used, regenerate its key, or create a replacement token. Either way the token uses the current scheme straight away, but anything that uses it must be given the new key.

Note: the email identifies each token by the first few characters of its name, its description and when it was created. It never contains a token's key.

What happens on the date

A token from the email that has still not been used stops working, and Magic Suite refuses requests made with it. To restore access, create a replacement token and give its key to whatever used the old one.

Reconnection

Reconnection

Reconnection

timed out

timed out

Attempt of

Reload
An unhandled error has occurred. Reload 🗙