Find the API tab
1
Open Company Profile
In the sidebar, under Settings, click Company Profile.

2
Pick the workspace and open API
Click the company whose data the integration will use, then open the
API tab.

Create a token
1
Name it, set an expiry, pick scopes
Click Create token.
- Name: what the token is for, such as the integration it belongs to. Up to 120 characters. Only people in the workspace see it.
- Expiration: Never expires, 30 days, 90 days, or 1 year. See Expiry.
- Scopes: at least one. See Choosing scopes.

2
Copy the token
Click Create token. The token is shown once. Click Copy and
store it in your integration’s secret manager or environment variables.
Sailer keeps only a hash of the token, so nobody can show it to you again.
This screen closes only when you click Done. If you lose the token,
revoke it and create a new one.

3
Check it works
Choosing scopes
The picker groups scopes by area, with one column per access level. Read covers listing and retrieving records. Write covers creating, updating and deleting them. All read selects every read scope, Select all selects everything, and Clear removes every scope.
Pick the narrowest set the integration needs. A token reads the whole workspace
within its scopes, whoever owns the records. A call without the right scope
returns
403 insufficient_scope, and the message names the missing scopes.
You can’t change a token’s scopes after creating it. To change them, create a
new token with the scopes you want, move the integration to it, then revoke
the old one.
Expiry
Once a token expires, the API answers
401 and the token’s status in the list
changes to Expired. You can’t extend a token. Create a new one before the
old one expires, then revoke the old one.
Use an expiry for anything temporary: a trial, a one-off import, or a
contractor’s access.
Revoke a token
Revoke a token when an integration is retired, when the person who set it up leaves, or whenever you think it might have leaked.1
Click revoke
In the token’s row, click the revoke icon at the end, then confirm.

2
It stops working immediately
The next request with that token gets
401. Revoking can’t be undone.
Statuses
Last used is updated at most every few minutes, so a token you just used
can still show an older time.
The legacy API key
Below the token list, Legacy API key shows the workspace’s singleX-API-KEY. Webhooks and older integrations use it; the /v1 API does not.
Use API tokens for anything new.
Regenerate replaces that key right away. Everything that uses the old key
stops working until you update it, so find those integrations first.
Good practice
- One token per integration, so revoking one never breaks the others.
- Keep tokens on the server. A token in browser or mobile code is a leak of the whole workspace.
- Keep tokens in environment variables or a secret manager, never in source control.
- If a token leaks, revoke it first and investigate afterwards.