Getting access

Ask us to switch the API on, then an HR admin creates credentials in the admin portal.

Switched on per organisationThis is built and working, and is switched on for each organisation on request. Ask your account manager, or reply to any email from us naming it.

1. Ask us to switch it on

The API is off for every organisation until you ask. Ask your Alltoogether account manager, or reply to any email from us, and we switch it on from our side.

2. Create credentials

An HR admin or organisation admin creates them in the admin portal, under Settings, API access, Create API credentials. Line managers and employees cannot.

Give the credentials a name, such as the system that will use them. Use one set per system.
Choose what they can read: Employees, Annual leave, Holidays.
Choose when they expire: 30, 90 or 180 days, or one year.
Accept the API Terms on behalf of your organisation. The version you accepted is recorded against the credentials.

3. Copy the client secret straight away

The client secret is shown once. Store it in your system's secret store (in Google Apps Script, Script Properties), never in a spreadsheet cell, a document, a repository or an email. If it is lost, revoke the credentials and create new ones.

Good to know

  • Up to five sets of credentials can be live at once.
  • Every HR admin is told, in the admin portal and by email, when credentials are created, and every use is logged.
  • Revoke on the credentials card stops them working on the next request, along with every token issued to them. The card shows when each set was last used, so unused ones are easy to spot.
  • If a secret may have been seen by someone who should not have it, revoke it, create a new one, and tell us at support@alltoogether.com.

On this page