API keys — your personal tokens
A personal token replaces your password login on a scanner. It is shown exactly once — there is no way to read it later. External programs get their own technical account, not your token.
A personal access token lets a program log in as you, without providing your password. It is used with mobile scanners — places where you are the person using the system on the other end.
An external program does not get your token. An integration, automation, or your own script uses the company’s technical account: a separate program account with its own token, assigned to one company and created by a company administrator under Settings → System → Technical accounts. The reason is simple: your token carries everything you can do across every company you can access — and will disappear with your account if you change jobs. A technical account makes it clear in the history which program changed something. See Company administrator and superadministrator — who bypasses what.
Step by step
- Click your avatar in the top-right corner and choose My profile.
- Open the Security tab and scroll to API keys.
- Click New token. The New access token dialog opens.
- Enter a descriptive Token name; the hint says e.g. Wrocław scanner #1.
- Optionally set Expires (optional). The hint says Leave empty for a token that does not expire.
- Click Create token.
- If 2FA is enabled, the system asks for a code — enter it.
- The dialog shows Your new token with the warnings The token will be shown only once. and Copy it now — we will not be able to recover it. Copy it and paste it into the device or script now.
- Close the dialog with Done.
- Check that the token works. If you lost it, there is nothing to recover — revoke it and issue a new one.
Creating a token
Click New token and enter:
- Token name — a description such as Wrocław scanner #1. It helps you identify the token in the list six months later.
- Expires (optional) — an expiration date. Leaving it blank means the token never expires; the list shows Never.
After creation, the system shows the token value once.
Copy it now. You cannot read it later — not even support or an administrator can. If you lose it, revoke it and issue another one.
What appears in the list
Name, Last used:, and Expires: (or Never). A token that has been cut off has the Revoked badge.
The “last used” column is especially useful: a token that no one has touched for months is usually for a scanner that no longer exists — and a good candidate for revocation.
Revoking a token
Revoke token cuts off access immediately; the system confirms with Token revoked. Click again to remove from list. A revoked token stays in the list as a record — use Remove from list separately to remove it from view.
Tokens are independent of sessions
This is the detail most often missed during an incident: “Log out all sessions” does not affect tokens. A scanner using a token continues to work even after every browser has been logged out (Sessions and devices — who is logged into your account).
With 2FA enabled
Creating and revoking tokens then requires additional confirmation with a code (Two-factor authentication (2FA) — enabling it, backup codes, and disabling it).
Good token hygiene
- One token per device or integration. One shared token for five scanners means reconfiguring all five if one is lost.
- Set an expiration date for anything temporary.
- A token is a secret equivalent to a password — do not send it in chat or email.
Want to see this with your orders? We’ll show you NOXTI with your sales channels and warehouse.
Book a demo