DevelopersPublic guide
Manage API tokens
Create, label, store, rotate and revoke tenant-scoped credentials without exposing the secret after issuance.
Outcome
Create, label, store, rotate and revoke tenant-scoped credentials without exposing the secret after issuance.
QuantifyQS keeps the working record understandable to a quantity surveyor and reconstructable by an authorised reviewer. The screen helps organise the work; the accountable professional still owns judgement and approval.
Before you start
- Approved integration and owner.
- Required scopes and expiry.
- A secure secret-storage destination.
Working method
- Confirm contextOpen the correct organisation and project, confirm your visible role, then check that source information and status are current.
- Make the controlled changeComplete the manage api tokens task in the relevant workspace. Use references, notes and structured fields instead of relying on memory or an offline copy.
- Review before issueCheck quantities, rates, dates, parties and evidence, then use the named review or approval state appropriate to the workflow.
- Retain the resultKeep the issued output and its project event together. Where a PDF or spreadsheet is exported, verify the generated file before sending it outside the workspace.
Evidence and checks
- Token purpose and creator are recorded.
- Secret is captured once into approved storage.
- Rotation and revocation events are retained.
Roles and boundaries
- Workspace role determines what a person may view or change; plan determines what the organisation has contracted to use.
- Customer-specific Firm and Enterprise panels do not widen a user role or cross the active tenant boundary.
- AI suggestions, imported data and generated documents require human review before professional reliance or issue.
Did this guide help?
Only your answer, guide slug and version are recorded.