Skip to main content
DocumentationDownload PDF
DevelopersPublic guide

Manage API tokens

Create, label, store, rotate and revoke tenant-scoped credentials without exposing the secret after issuance.

Outcome

Create, label, store, rotate and revoke tenant-scoped credentials without exposing the secret after issuance.

QuantifyQS keeps the working record understandable to a quantity surveyor and reconstructable by an authorised reviewer. The screen helps organise the work; the accountable professional still owns judgement and approval.

Before you start

  • Approved integration and owner.
  • Required scopes and expiry.
  • A secure secret-storage destination.

Working method

  1. Confirm contextOpen the correct organisation and project, confirm your visible role, then check that source information and status are current.
  2. Make the controlled changeComplete the manage api tokens task in the relevant workspace. Use references, notes and structured fields instead of relying on memory or an offline copy.
  3. Review before issueCheck quantities, rates, dates, parties and evidence, then use the named review or approval state appropriate to the workflow.
  4. Retain the resultKeep the issued output and its project event together. Where a PDF or spreadsheet is exported, verify the generated file before sending it outside the workspace.

Evidence and checks

  • Token purpose and creator are recorded.
  • Secret is captured once into approved storage.
  • Rotation and revocation events are retained.

Roles and boundaries

  • Workspace role determines what a person may view or change; plan determines what the organisation has contracted to use.
  • Customer-specific Firm and Enterprise panels do not widen a user role or cross the active tenant boundary.
  • AI suggestions, imported data and generated documents require human review before professional reliance or issue.