To create your API credentials, follow the steps outlined below:
easycms.fi/admin cloud console.Setup > Accounts.API settings tab.WebAPPs or B2B Mobile app tab depending on your needs.Active.Callback URL in the provided field.
Update to save the settings.The API accepts two mutually exclusive authentication modes. A request uses exactly one of them — never a mix of both:
| Legacy mode (WebAPPs / B2B Mobile app) | Token mode (Inventory Manager app) | |
|---|---|---|
| 1 | API KEY — sent in the Authorization1 header |
not used — no header at all |
| 2 | API ACCOUNT ID — account parameter |
API ACCOUNT ID — account parameter |
| 3 | API USERNAME — username parameter |
Token username — username parameter |
| 4 | API PASSWORD — password parameter |
not used — the token replaces it |
| 5 | — | TOKEN — token parameter (the token value itself) |
Authorization1 header.Once the steps above are completed, you will have the following four elements necessary for your legacy API connection:
You can manually change the API username and password at any time.
https://easycms.fi/public_api/.TOKEN used in the Authorization1 header is the same as your API KEY.user_email)When your application calls a setter endpoint (set_product, set_stock, set_order, set_purchase_order, …) on behalf of one of its own users, it may include a user_email parameter in the request to identify which user made the call. This works identically in both authentication modes:
| Parameter | Type | Description |
|---|---|---|
user_email |
string | OPTIONAL. Email address of the application user who performed the action. Sent like any other body parameter (JSON body field, form field or query string). Must be a syntactically valid email address. |
API-{username} - {user_email} — for example API-Shop_1 - [email protected] — in the Activity Log page and in the stock movement appuser columns, so you can see which app user made each API change.API-{username} actor exactly as before.curl -X POST 'https://easycms.fi/public_api/set_stock' \
-H 'Authorization1: TOKEN' \
-d 'username=Shop_1&password=***&account=12&pid=34&location_id=1&shelf_id=1&stock=5&reason=1&[email protected]'
The Inventory Manager tab uses token-based authentication instead of a single username and password. This lets one account issue a separate credential to every device or user of the app — and a token login needs no API key and no password at all.
Mobile applications that log a specific CMS user in (e.g. warehouse picking)
use a second, smaller credential on TOP of the account API credentials: a
per-user login token rendered as a QR code. An account can have many users —
every API call still authenticates the ACCOUNT first (one of the two modes
above), and the user is verified second via the public
verify_user endpoint with the user_token parameter.
Setup > Accounts > API settings > Inventory Manager.API Tokens, click Add token and enter a Username — a secure token is generated automatically.Update to save. You can add as many tokens as you need.A token login sends exactly three request fields — nothing else is required or checked:
token parameter.username parameter.account parameter.There is no Authorization1 header, no API key and no password in token mode:
curl -X POST 'https://easycms.fi/public_api/get_products' \
-d 'username=TOKEN_USERNAME&token=TOKEN_VALUE&account=ACCOUNT_ID&start=0&limit=10'
Compatibility note: older app versions sent the token value in the
passwordfield together with theAuthorization1API-key header. That compatibility path has been removed — if your app still authenticates that way, update it to send thetokenparameter (or re-scan the QR code below) .
Each token row has its own QR code button, and every QR contains only the fields its mode actually uses:
username, token (the token value), account
(API account ID) and endpoint (the URL the app should call) — scanning it with the
app configures the connection instantly.token (the API KEY), username,
password, account and endpoint — the four legacy login fields plus the endpoint.Update — that token stops working immediately.Remember to store your API credentials securely and never share them publicly.