Última actualización:

Manage service user API tokens

Learn how to create, revoke, delete, and regenerate service user API tokens to securely connect external systems via the web app.

What are the differences between service user and user API tokens?

Service user and user API tokens offer flexible ways to connect external tools to SafetyCulture.

  • Service user API tokens are best suited for long-term or shared integrations where access should stay the same regardless of user changes. You can set their permissions, which makes them ideal for stable, system-level connections.

  • User API tokens are suitable for one-off tasks, personal workflows, or scenarios where access needs to reflect a specific user's permissions or group and site memberships.

Choosing the correct token type ensures your integration runs smoothly while matching your organization's security and access needs.

Functionality

Service user API token

User API token

Ownership

Created for a service user (system-based or integration-focused)

Created by an individual user

Login

Cannot be used to log in

Can be used to log in

Permissions

Assigned for each service user

Inherits the user’s permission set

Group and site access control

Not supported

Inherits access from the user

Integrations

Designed for long-term or shared integrations

Suited for short-term or personal use

Token stability

Not affected by user changes

Will expire if user is deactivated or exits the organization

Activity logs

Shows the service user name

Shows the individual user’s name

Visibility

Not shown in the user list

Visible in user settings

Billing

Does not count toward seat billing

Counts toward assigned user seat

Each user can create up to 10 active user API tokens. Whereas, each organization can have up to 20 active service user tokens.

If you belong to multiple organizations, you need to create separate API tokens for your integrations. This applies to both service user and user API tokens.

If you're using a service user API token for SCIM provisioning, the service user must have both Permiso de "Administración de plataformas: Usuarios" and Permiso para "Administración de plataformas: Grupos".

Create a service user API token

  1. Log in to the web app.

  2. Click your organization name on the lower-left corner of the page and select Integraciones.

  3. Select API tokens from the tab at the top of the page.

  4. Click Icono PlusCreate API token on the upper-right of the page. Create a service user API token from the API tokens tab via the web app.

  5. Complete the following details: Create a service user API token via the web app.

    • Enter a name for the service user API token to describe its purpose.

    • Choose how long the token remains active before it expires due to inactivity. You can select 31, 45 (default), 60, or 180 days.

    • Select the permission sets for the service user. All permissions are selected by default.

  6. Click Create token on the lower-right of the page.

  7. In the pop-up window, click the service user API token to copy it. Save the token securely before closing the window.

Edit a service user API token

  1. Log in to the web app.

  2. Click your organization name on the lower-left corner of the page and select Integraciones.

  3. Select API tokens from the tab at the top of the page.

  4. Click the active service user API token you want to edit.

  5. Click Icono del lápiz on the upper-left of the page to change the token name.

  6. On the left-hand side of the page, click Editar to change how long the token remains active before it expires due to inactivity. You can select 31, 45 (default), 60, or 180 days.

  7. On the right-hand side of the page, click Editar to update the service user's permission sets.

  8. Click Guardar cambios.

View service user API tokens list

  1. Log in to the web app.

  2. Click your organization name on the lower-left corner of the page and select Integraciones.

  3. Select API tokens from the tab at the top of the page.

  4. Under Service user API tokens, view the list of tokens. View service user API tokens list via the web app.

Revoke a service user API token

  1. Log in to the web app.

  2. Click your organization name on the lower-left corner of the page and select Integraciones.

  3. Select API tokens from the tab at the top of the page.

  4. Under Service user API tokens, click Revoke next to the token. Revoke a service user API token via the web app.

  5. In the pop-up window, click Revocar.

Regenerate a revoked service user token

  1. Log in to the web app.

  2. Click your organization name on the lower-left corner of the page and select Integraciones.

  3. Select API tokens from the tab at the top of the page.

  4. Under Service user API tokens, click Regenerate next to the revoked token. Regenerate a revoked service user token via the web app.

  5. In the pop-up window, click Confirmar.

  6. Click the service user API token to copy it. Save the token securely before closing the window.

Delete a revoked service user token

  1. Log in to the web app.

  2. Click your organization name on the lower-left corner of the page and select Integraciones.

  3. Select API tokens from the tab at the top of the page.

  4. Click More vertical icon next to the revoked service API token.

  5. Select Delete iconEliminar. Delete a service user API token via the web app.

  6. In the pop-up window, click Delete.

Frequently asked questions

It depends on how your integration is set up.

  • For custom-built integrations (such as Workato, scripts, or direct API calls using a service user or user API token): Yes. Regenerating the token will break the integration until the replacement token is manually updated in your integration settings.

  • For built-in SafetyCulture integrations (such as Power BI, Microsoft Teams, or SharePoint): No. These integrations use system-managed tokens, so revoking or regenerating your API tokens will not affect them.

Revoking a service user API token immediately stops it from working, but you can still regenerate it later. This is helpful if you want to pause an integration temporarily without removing the token entirely.

Deleting a service user API token permanently removes it from your organization. You can only delete a token after revoking it. Once deleted, the token can't be recovered or regenerated, so you'll need to create a new one if you want to reconnect the integration.

¿Necesita más ayuda?
En este artículo