Skip to Content
API referenceAPI tokens

Developer reference

Create and revoke API tokens

Use named minimum-scope credentials for integrations and keep their lifecycle separate from browser sessions.

Create a separate token for each integration. A descriptive name and minimum scopes make later review and revocation easier.

Create a read-only token

  1. Sign in to the intended Helm account.
  2. Open Settings → API tokens.
  3. Give the integration a recognizable name.
  4. Select read:finance for a financial read-only client.
  5. Copy the secret when shown and store it in your integration’s server-side secret store.

Use imports:read separately when the client needs import-job inspection. Do not add write or deletion permission for convenience.

Management endpoints

MethodPathPurpose
GET/api/v1/api-tokensList token metadata.
POST/api/v1/api-tokensCreate a token.
DELETE/api/v1/api-tokens/:idRevoke an owned token.

A Helm-token caller needs manage:tokens for these registered management operations. Metadata is not a way to retrieve an old secret.

Revoke or replace

Revoke a credential when its integration ends or it is exposed. Update the integration to a newly issued minimum-scope credential and verify its intended request. Do not keep a leaked token as a fallback.

Browser sign-out and API-token revocation are different actions. Signing out of one browser does not delete all integration tokens.

Never put a token in a URL, client bundle, screenshot or full request log. Continue with scopes and quickstart.