Get Access
Before you can call the APIs you need credentials issued by Tipsoi. This page explains how access works and what you’ll receive.
Requesting credentials
API access is granted per organization. Contact your Tipsoi account manager to start; you’ll agree on which integration path and which API surfaces you need, and Tipsoi provisions an account scoped to your use case.
- Software (HRM) API — you receive an
emailandpasswordused to sign in. - Device Portal API — you receive a
usernameandpassword.
Test credentials for the sandbox and production credentials are issued separately. You can start building against the sandbox while onboarding completes.
How authentication works
Both APIs use JWT bearer tokens. You exchange your credentials for a token once, then send that token on every request. There are no long-lived API keys to manage, and tokens expire, so a leaked token has a limited window.
The full sign-in flow with a working example is on the Quick Start page.
Keep credentials safe
- Store credentials and tokens server-side only. Never embed them in client apps, mobile bundles, or public repositories.
- Never put a token in a URL or query string.
- Rotate credentials if you suspect exposure, and contact Tipsoi to revoke.