تخطَّ إلى المحتوى

Tokens and scopes

هذا المحتوى غير متوفر بلغتك بعد.

A client is one connected system owned by one company — “D365 production”, say. It is not a person. Each client holds up to two live tokens and a set of scopes.

  1. A company administrator with the permission Manage integrations opens Settings → Integrations → New client in the Slflo console.
  2. They give it a name, pick the ERP (DYNAMICS365, SAP, ODOO, ORACLE or OTHER) and tick only the scopes it needs. An IP allow-list (single addresses or CIDR blocks) is optional.
  3. The token — sfi_live_ followed by 43 characters — is shown once. Store it encrypted in your ERP’s settings. Slflo keeps only a hash of it.
  4. Send it on every call as Authorization: Bearer sfi_live_…, and check it with GET /me.

The token names the company. There is no parameter to reach another company’s data.

Scope Allows
orders:read / orders:write Pull orders / ack them
invoices:read / invoices:write Pull invoices / ack them
payments:read / payments:write Pull payments (receipts, cheques, reversals) / ack them
returns:read / returns:write Pull returns (credit notes) / ack them
customers:read / customers:write Look up / push customers and branches
catalog:write Push units, products and their sellable units
prices:write Push price lists and prices
balances:write Push customer balances
stock:read / stock:write Look up warehouses only; v1 has no stock operations yet
visits:read, webhooks:manage Nothing in v1 yet — leave them unticked

A call without the scope it needs answers 403 SCOPE_MISSING, and the error names the scope. GET /me and the reference lists need no scope. GET /lookup takes any scope of the record’s family.

Tokens last 12 months; GET /me shows token_expires_at. A client holds at most two live tokens. To rotate without a gap:

  1. In the console, open the client and Rotate: a second token is issued; the first still works. (With two live tokens already, Rotate is refused — revoke the one the ERP no longer uses first.)
  2. Put the new token in your ERP and check it with GET /me.
  3. Revoke the old token. Revocation is immediate — the next call with it answers 401 TOKEN_REVOKED.

The hosted sandbox is a company of its own, and its tokens are ordinary tokens of that company: they start with sfi_live_ and work like any other. What makes them sandbox tokens is the company they open, which GET /me names in data.company. See Sandbox access.

Only a copy of Slflo you run yourself, seeded with the demo company, issues a token that starts with sfi_test_. It behaves exactly like a live one; the prefix only tells you, and secret scanners, that it came from a development seed.

Terminal window
curl -s "$SLFLO_BASE/me" -H "Authorization: Bearer $SLFLO_TOKEN" | jq '{scopes: .data.scopes, expires: .data.client.token_expires_at}'
curl -s "$SLFLO_BASE/me" -H "Authorization: Bearer sfi_live_wrong" | jq .error.code # "TOKEN_INVALID"

SLFLO_BASE is https://api.slflo.com/api/integration/v1, as in the quickstart.