Tokens and scopes
A client is one connected system owned by one company — “D365 production”, say. It is not a person. Each client holds up to two live tokens and a set of scopes.
Getting a token
Section titled “Getting a token”- A company administrator with the permission Manage integrations opens Settings → Integrations → New client in the Slflo console.
- They give it a name, pick the ERP (
DYNAMICS365,SAP,ODOO,ORACLEorOTHER) and tick only the scopes it needs. An IP allow-list (single addresses or CIDR blocks) is optional. - The token —
sfi_live_followed by 43 characters — is shown once. Store it encrypted in your ERP’s settings. Slflo keeps only a hash of it. - Send it on every call as
Authorization: Bearer sfi_live_…, and check it withGET /me.
The token names the company. There is no parameter to reach another company’s data.
Scopes
Section titled “Scopes”| Scope | Allows |
|---|---|
orders:read / orders:write |
Pull orders / ack them |
invoices:read / invoices:write |
Pull invoices / ack them |
payments:read / payments:write |
Pull payments (receipts, cheques, reversals) / ack them |
returns:read / returns:write |
Pull returns (credit notes) / ack them |
customers:read / customers:write |
Look up / push customers and branches |
catalog:write |
Push units, products and their sellable units |
prices:write |
Push price lists and prices |
balances:write |
Push customer balances |
stock:read / stock:write |
Look up warehouses only; v1 has no stock operations yet |
visits:read, webhooks:manage |
Nothing in v1 yet — leave them unticked |
A call without the scope it needs answers 403 SCOPE_MISSING, and the error names the scope.
GET /me and the reference lists need no scope.
GET /lookup takes any scope of the record’s family.
Expiry and rotation
Section titled “Expiry and rotation”Tokens last 12 months; GET /me shows token_expires_at. A client holds at most two live
tokens. To rotate without a gap:
- In the console, open the client and Rotate: a second token is issued; the first still works. (With two live tokens already, Rotate is refused — revoke the one the ERP no longer uses first.)
- Put the new token in your ERP and check it with
GET /me. - Revoke the old token. Revocation is immediate — the next call with it answers
401 TOKEN_REVOKED.
Sandbox tokens
Section titled “Sandbox tokens”The hosted sandbox is a company of its own, and its tokens are ordinary tokens of that company:
they start with sfi_live_ and work like any other. What makes them sandbox tokens is the company
they open, which GET /me names in data.company. See Sandbox access.
Only a copy of Slflo you run yourself, seeded with the demo company, issues a token that starts
with sfi_test_. It behaves exactly like a live one; the prefix only tells you, and secret
scanners, that it came from a development seed.
Try it
Section titled “Try it”curl -s "$SLFLO_BASE/me" -H "Authorization: Bearer $SLFLO_TOKEN" | jq '{scopes: .data.scopes, expires: .data.client.token_expires_at}'curl -s "$SLFLO_BASE/me" -H "Authorization: Bearer sfi_live_wrong" | jq .error.code # "TOKEN_INVALID"SLFLO_BASE is https://api.slflo.com/api/integration/v1, as in the
quickstart.

