Create an API token#

  1. Open Settings → API Tokens

    You need the manage security permission (Owner or Admin).
  2. Select Create API token

    Give the token a name (for example HR system – production).
  3. Choose the scopes

    Tick only the scopes the integration needs (see below).
  4. Choose the expiration

    A number of days, or Never.
  5. Copy the token now

    The full token is shown once. IVQA stores only a hash of it and its prefix. If you lose it, revoke it and create a new one.

[SCREENSHOT REQUIRED]

Settings → API Tokens

The API Tokens tab of Settings with the token list and the Create API token form

expected file: public/images/api/api-tokens.png

The token list shows each token's name, prefix, scopes, last used and expiry, with Revoke and Delete actions. Creating, revoking and deleting tokens is recorded in the activity logs.

Send the token#

GET /api/ext/ping HTTP/1.1
Host: api.ivqa.org
Authorization: Bearer ivqa_XXXXXXXXXXXXXXXXXXXX

Clients that cannot set Authorization may use X-IVQA-Token: <token> instead.

GET /api/ext/ping validates a token and returns its account and scopes — use it right after creating a token.

Scopes#

ScopeGrants
credentials:readdashboard, statistics, activity, documents, students, employees, search, verification status
verify:readQR code generation (/qr)
verify:writecreate verifications, metadata sync, student and employee document issuance

ping, profile, organization and settings need a valid token but no specific scope. Beyond scopes, the API applies the role permissions of the token's creator and the profile of the workspace: an institution token cannot list employees, and a token whose creator cannot view students gets 403 forbidden on /students.

Rate limit#

120 requests per 600 seconds per token. Above that, the API answers 429 with Retry-After: 600.

How the add-ons authenticate#

The official Google Workspace and Microsoft Office add-ons do not ask users to paste tokens: users sign in inside the add-on with their IVQA account and, when they belong to several organizations, choose the workspace. That sign-in flow is reserved for the IVQA add-ons. Your own integrations use API tokens as described above; the tokens follow the same scopes and limits.

Security notes#

  • Treat tokens like passwords: store them in a secrets manager, never in a document or a spreadsheet.
  • Give each integration its own token with the smallest scopes and an expiry.
  • Revoke a token as soon as it is no longer needed; revocation is immediate.