API Permissions
Roles, menus, screen aliases, and system menus
Overview
Your IT team or third-party suppliers can authenticate and run eligible
APIs to create processes and activities outside of the Catch-e application.
For example, a Novated Lease Calculator on your website.
Role Access
To check role access to APIs
System / Roles - select the target role record
API Access - if this field is checked, the Roles / Apis tab will be available.
Roles / API tab
The Roles / API tab is only shown for roles where "Access Type" is 'web-services'.
'web_services' is a standard role with this access type.
Only 'admin' users can view this tab and enable/disable permissions.
Available permissions are listed in alphanumeric order.
Go to the APIs page to see a list of the APIs that these permissions enable.
Note: To optimise security, only enable permissions for the individual APIs that you need.
Permissions
Action Buttons
Legend
Permission - The permission is available by default
Permission (Restricted) - This permission is not visible on the Roles / APIs screen unless it has been configured for external use. Contact your Account Manager to discuss
Role Permissions
All roles can generate a token from the authenticate API.
But other APIs can only be run if the role has permission to do so.
To optimise security, only enable necessary API permissions for the role.
To review or enable permissions for a role.
System / Roles - select the target role record
Navigate to the Roles / Apis tab
Edit and check on the required permissions
If you are not actively using an API, leave the permission off for better security.
Logins
Create separate logins for each API process and each supplier also.
If issues arise, it is easier to investigate if the role and user are clearly identifiable.
This also makes it easier for you to decommission an API process by suspending the related login/s without affecting other system areas.
Key fields from sample records are shown below:
Example Set-up
Role / User - Web Quotes
Role
Role 'abc'
Access Type 'web-services'
API Access Image:Check-box on.gif
User
User Login 'webquote_ABC'
Role 'abc'
Organisation 'ABC Web Development'
Role / User - CRM
Role
Role 'crm'
Access Type 'web-services'
API Access Image:Check-box on.gif
User
User Login 'crm_client_data'
Role 'crm'
Organisation 'CRM Company'
Role / User - Fleet Manager
Role
Role 'fleet_manager'
Access Type 'external'
Restrict Key 'client_id'
API Access Image:Check-box on.gif
User
User Login 'Fancy Fleet'
Role 'fleet_manager'
Organisation 'Fancy Fleet'