API
Other programs access the DocSecBox through the application programming interface (API). On this page you see the address of the interface, set where requests may come from, and register the applications that may use it.
Paid add-on module
API access is a paid add-on module. Without the module there is no API entry under Settings › Application. The License page shows whether it is licensed.
Administrators only
Only administrators see this page. If Only super administrators are allowed to adjust program settings is switched on under Roles, only super administrators see it.
Address of the interface
The Interface card gives the address at which other programs reach the API, under Base URL of the HTTP REST API. The API documentation link opens a description of the interface. The complete specification is available on request from the operator of your DocSecBox or from the manufacturer.
Allow access
The API only accepts requests from origins you have allowed. Both options are off by default. While both are off, the API refuses every request, and the page points this out.
- Open Settings › Application › API.
- In the API access control card, select one or both options: Allow access from internal IP address ranges and Allow access from external IP address ranges.
- Click Save settings.
What counts is the address a request arrives from. A call from the server itself counts as neither internal nor external. Neither option refuses it.
Register an application
You register every program that uses the API as an application. In doing so you decide which users receive a key for it.
- In the API applications card, click Register application.
- In the Add API application dialog, enter a name under Name of the application.
- In the user list, select the accounts that should receive a key. The Search for user... field helps with long lists.
- Click Save.
On saving, every ticked account receives a key. If you later clear a tick, that account's key is revoked. Only the user can see the key, in the profile under Third-Party Keys. It is never shown on this page.
The list of applications shows the Name, the number of Users with a key and the State of each one: Active, Active until a date, or Deactivated. Use Edit to change an application in the Edit API application dialog.
Take an application out of service
An application cannot be deleted. You take it out of service with a date:
- In the application's row, click Edit.
- Select Deactivate from a date and choose the date under Deactivated.
- Click Save.
Until that date, the users' keys remain valid.