Skip to main content

Api Credentials

Api Credentials

Purpose and when to use this record

Grant an ecommerce integration only the product, page, store, order, tracking, status, or shipping capabilities it needs.

At a glance

  • Identify it by: Name, and Allow Write Order Status.

  • Check its business context: Store.

  • Why care: Availability and publication flags affect future use without erasing history. Prefer disabling an obsolete setup record when existing transactions still refer to it.

  • Why care: Grant the smallest capability and shortest practical lifetime. Treat any generated secret as confidential; copy it at creation time and never place it in notes or screenshots.

Before you begin

You need the Brisk storespermission for the action you are taking on api credentialscredentials. asIf parta ofCreate, theEdit, ecommerceor module.Delete This generated referencecontrol is awaitingabsent, workflowdo review.not work around it with another user’s account; ask an administrator to review your role.

Have valid Store records ready first. Those selections determine where this API Credential belongs and which later screens can find it.

Create aan recordAPI Credential

Brisk Api Credentials create screen displayed with fictional documentation-demo data.
The Api Credentials create screen in the Brisk documentation demo.

TheCreate evidencean packetAPI identifiesCredential for one identifiable integration or device. Do not share one credential across unrelated systems because revocation and audit history would become ambiguous.

  1. Select the viewbusiness context first: Store.

  2. Enter the required identifying and operational values: Store, and Name.

  3. Review Is Active, Allow Read Products, Allow Read Pages, Allow Read Store, Allow Read Orders, and Allow Write Tracking, plus the remaining screen fields deliberately; these choices control availability or workflow rather than merely describing the record.

  4. Save the API Credential, then confirm Name, and Allow Write Order Status on its detail page before continuing.

After saving: Give the generated secret only to the named client, test each granted capability, and disable the credential promptly if its source locationnetwork foror owner changes.

Delete an API Credential

Disable or revoke this action.API ConfirmCredential user-facingwhen stepsaccess beforemust approvingstop. thisDelete page.it only after its audit value is no longer needed and the integration has been moved to a replacement credential.

If the record is merely obsolete, use Is Active to remove it from future use while preserving existing references.

On the confirmation page, verify Name, and Allow Write Order Status. After confirmation, return to the API Credentials list and make sure only the intended API Credential was removed.

ViewReview recordAPI Credential details

The evidence packet identifiesUse the viewdetail page as the shared record of what this API Credential currently means. Verify Is Active, and sourceAllow locationWrite Order Status before relying on it for thisa action.decision.

Confirm

Follow user-facingStore stepsto beforedetermine approvingwhether the issue is on this API Credential or on one of those linked records.

Next check: Give the generated secret only to the named client, test each granted capability, and disable the credential promptly if its source network or owner changes.

Edit an existing API Credential

Edit this API Credential to reduce access, rotate ownership, set an expiration, or disable the integration. Create a separate credential when the calling system changes.

  1. Open the detail page. Compare Store with the supporting document or approved request.

  2. Recheck Is Active, and Allow Write Order Status. These values are most likely to change storefront visibility, customer communication, payment, or fulfillment.

  3. Save the change, return to the list, and confirm that the API Credential now appears under the expected Is Active, and Allow Write Order Status.

After the change: Give the generated secret only to the named client, test each granted capability, and disable the credential promptly if its source network or owner changes.

Find and review recordsapi credentials

Brisk Api Credentials list screen displayed with fictional documentation-demo data.
The Api Credentials list screen in the Brisk documentation demo.

The evidence packet identifiesUse the viewApi Credentials list to find the correct record before opening or changing it. Compare Name, and sourceAllow locationWrite Order Status. Records with similar names or numbers can still belong to different Store.

  • Keyword search checks Name.

  • Narrow the list with Store filters.

  • The initial order emphasizes Name. Select a column heading when you need a different comparison.

Open the API Credential whose Name, and Allow Write Order Status match the task. If it is missing, clear the list filters and recheck Store, Is Active, and Allow Write Order Status rather than creating a replacement immediately.

Fields and business rules

Brisk stores 15 user-relevant fields for this action.API ConfirmCredential, user-facingincluding steps1 beforelinked-record approvingselection and 0 controlled-choice fields. Create and edit screens may hide calculated or workflow-managed values from this page.full reference.

Editanexistingrecord

sourcelocation user-facingstepsbefore

The

evidencepacketview user-facingstepsbefore
Field RequiredWhat it controls
StoreYesThe evidencestore packetassociated identifieswith thethis viewAPI andcredential.
NameYesHuman-readable name for this action.API Confirmcredential.
Is approvingActiveNoWhether this page.

API

Deletecredential ais record

active.
Allow identifiesRead theProducts NoWhether this API credential allows read products.
Allow Read PagesNoWhether this API credential allows read pages.
Allow Read StoreNoWhether this API credential allows read store.
Allow Read OrdersNoWhether this API credential allows read orders.
Allow Write TrackingNoWhether this API credential allows write tracking.
Allow Write Order StatusNoWhether this API credential allows write order status.
Allow Quote ShippingNoWhether this API credential allows quote shipping.
Expires AtNoDate and sourcetime locationrecorded for expires at on this API credential.
Allowed Ip CidrsNoOptional newline/comma-separated list of allowed IP or CIDR ranges.
Last Used AtNoDate and time recorded for last used at on this API credential.
Last Used IpNoThe last used IP recorded for this action.API Confirmcredential.
Last approvingRotated AtNoDate and time recorded for last rotated at on this page.API credential.

What happens next

Give the generated secret only to the named client, test each granted capability, and disable the credential promptly if its source network or owner changes.

Common mistakes and troubleshooting

  • The record will not save: Recheck Store, and Name and any message beside the field. A required related record may also be inactive or unavailable to your role.

  • The record saved but is not available where expected: Recheck Is Active, and Allow Write Order Status, then clear the filters on the destination list. A saved record can still be inactive, unpublished, locked, unapproved, or in the wrong workflow state.

  • The values look right but the result is wrong: Open Store from the detail page. Correct the specific relationship that is wrong instead of forcing a total or status to compensate for it.