Create an API token#
Open Settings → API Tokens
You need the manage security permission (Owner or Admin).Select Create API token
Give the token a name (for example HR system – production).Choose the scopes
Tick only the scopes the integration needs (see below).Choose the expiration
A number of days, or Never.Copy the token now
The full token is shown once. IVQA stores only a hash of it and its prefix. If you lose it, revoke it and create a new one.
[SCREENSHOT REQUIRED]
Settings → API Tokens
The API Tokens tab of Settings with the token list and the Create API token form
expected file: public/images/api/api-tokens.png
The token list shows each token's name, prefix, scopes, last used and expiry, with Revoke and Delete actions. Creating, revoking and deleting tokens is recorded in the activity logs.
Send the token#
GET /api/ext/ping HTTP/1.1
Host: api.ivqa.org
Authorization: Bearer ivqa_XXXXXXXXXXXXXXXXXXXX
Clients that cannot set Authorization may use X-IVQA-Token: <token> instead.
GET /api/ext/ping validates a token and returns its account and scopes — use it right after creating a token.
Scopes#
| Scope | Grants |
|---|---|
credentials:read | dashboard, statistics, activity, documents, students, employees, search, verification status |
verify:read | QR code generation (/qr) |
verify:write | create verifications, metadata sync, student and employee document issuance |
ping, profile, organization and settings need a valid token but no specific scope. Beyond scopes, the API applies the role permissions of the token's creator and the profile of the workspace: an institution token cannot list employees, and a token whose creator cannot view students gets 403 forbidden on /students.
Rate limit#
120 requests per 600 seconds per token. Above that, the API answers 429 with Retry-After: 600.
How the add-ons authenticate#
The official Google Workspace and Microsoft Office add-ons do not ask users to paste tokens: users sign in inside the add-on with their IVQA account and, when they belong to several organizations, choose the workspace. That sign-in flow is reserved for the IVQA add-ons. Your own integrations use API tokens as described above; the tokens follow the same scopes and limits.
Security notes#
- Treat tokens like passwords: store them in a secrets manager, never in a document or a spreadsheet.
- Give each integration its own token with the smallest scopes and an expiry.
- Revoke a token as soon as it is no longer needed; revocation is immediate.