API Credentials

API Credential Creation Guide

To create your API credentials, follow the steps outlined below:

Step 1: Log in to the CMS Console

  • Navigate to the easycms.fi/admin cloud console.
  • Log in with your credentials to access the dashboard.

Step 2: Access API Settings

  • Once logged in, proceed to Setup > Accounts.
  • Go to the API settings tab.
  • Here, you can select either the WebAPPs or B2B Mobile app tab depending on your needs.
  • Activate the synchronization by toggling the corresponding switch to Active.

Step 3: Configure Callback URL

  • Enter your Callback URL in the provided field.
    • This is essential for two-way synchronization.
    • It allows your CMS to send callback notifications to your application's core, enabling updates on CMS events.

Step 4: Set Up API Credentials

  • Input a username and password for your API.
  • Click Update to save the settings.

The Two Authentication Modes

The API accepts two mutually exclusive authentication modes. A request uses exactly one of them — never a mix of both:

Legacy mode (WebAPPs / B2B Mobile app) Token mode (Inventory Manager app)
1 API KEY — sent in the Authorization1 header not used — no header at all
2 API ACCOUNT ID — account parameter API ACCOUNT ID — account parameter
3 API USERNAME — username parameter Token username — username parameter
4 API PASSWORD — password parameter not used — the token replaces it
5 — TOKEN — token parameter (the token value itself)
  • Legacy mode authenticates with four things: the API key, the API account ID, the API username and the API password.
  • Token mode authenticates with three things only: the token, the token's username and the API account ID. No API key, no password, no Authorization1 header.
  • The two modes never interfere with each other: the API key selects which integration's credentials are checked, and token logins are only matched against the account's Inventory Manager token rows.

API Elements (Legacy Mode)

Once the steps above are completed, you will have the following four elements necessary for your legacy API connection:

  1. API KEY: Automatically generated by the system.
  2. API ACCOUNT ID: Automatically generated by the system.
  3. API USER NAME: The username you have entered.
  4. API PASSWORD: The password you have entered.

You can manually change the API username and password at any time.

API Access Endpoint

  • The main URL or endpoint for API access is https://easycms.fi/public_api/.

How to Generate a Token

  • In legacy mode, the TOKEN used in the Authorization1 header is the same as your API KEY.
  • In token mode, tokens are generated per device/user in the Inventory Manager tab — see below.

Identifying the Application User (Optional user_email)

When your application calls a setter endpoint (set_product, set_stock, set_order, set_purchase_order, …) on behalf of one of its own users, it may include a user_email parameter in the request to identify which user made the call. This works identically in both authentication modes:

Parameter Type Description
user_email string OPTIONAL. Email address of the application user who performed the action. Sent like any other body parameter (JSON body field, form field or query string). Must be a syntactically valid email address.
  • This parameter is never mandatory and is not checked against any account — it is an attribution hint for the logs only.
  • When provided and valid, the CMS activity logs attribute the write to API-{username} - {user_email} — for example API-Shop_1 - [email protected] — in the Activity Log page and in the stock movement appuser columns, so you can see which app user made each API change.
  • When omitted (or not a valid email), the logs show the plain API-{username} actor exactly as before.
curl -X POST 'https://easycms.fi/public_api/set_stock' \
-H 'Authorization1: TOKEN' \
-d 'username=Shop_1&password=***&account=12&pid=34&location_id=1&shelf_id=1&stock=5&reason=1&[email protected]'

Token-Based Authentication (Inventory Manager App)

The Inventory Manager tab uses token-based authentication instead of a single username and password. This lets one account issue a separate credential to every device or user of the app — and a token login needs no API key and no password at all.

Mobile App Login QR (per-user, on top of the account API credentials)

Mobile applications that log a specific CMS user in (e.g. warehouse picking) use a second, smaller credential on TOP of the account API credentials: a per-user login token rendered as a QR code. An account can have many users — every API call still authenticates the ACCOUNT first (one of the two modes above), and the user is verified second via the public verify_user endpoint with the user_token parameter.

  • The user QR encodes only the token string — no domain, no account id, no JSON wrapper. The app takes the server and the account from its configured API credentials; scanning the QR only identifies which user is using it.
  • It is NOT the API username/password — it is a randomly generated string that an admin (or the user themself) can regenerate at any time; regenerating instantly invalidates the old QR.
  • Generate it in the CMS: Users → user → Mobile app tab, the Employees editor (linked CMS user), or My profile.
  • One active QR per user; disabling the CMS user or deleting it also invalidates the token.

Creating Tokens

  • Go to Setup > Accounts > API settings > Inventory Manager.
  • Activate the synchronization switch.
  • Under API Tokens, click Add token and enter a Username — a secure token is generated automatically.
  • Click Update to save. You can add as many tokens as you need.

Authenticating with a Token

A token login sends exactly three request fields — nothing else is required or checked:

  1. Token — the token value itself, sent in the token parameter.
  2. Username — the token's username, sent in the username parameter.
  3. API ACCOUNT ID — your account's main admin ID, sent in the account parameter.

There is no Authorization1 header, no API key and no password in token mode:

curl -X POST 'https://easycms.fi/public_api/get_products' \
-d 'username=TOKEN_USERNAME&token=TOKEN_VALUE&account=ACCOUNT_ID&start=0&limit=10'

Compatibility note: older app versions sent the token value in the password field together with the Authorization1 API-key header. That compatibility path has been removed — if your app still authenticates that way, update it to send the token parameter (or re-scan the QR code below) .

QR Code Provisioning

Each token row has its own QR code button, and every QR contains only the fields its mode actually uses:

  • Token QR (Inventory Manager): username, token (the token value), account (API account ID) and endpoint (the URL the app should call) — scanning it with the app configures the connection instantly.
  • Legacy QR (WebAPPs / B2B Mobile app): token (the API KEY), username, password, account and endpoint — the four legacy login fields plus the endpoint.

Revoking Access

  • Remove the token row and click Update — that token stops working immediately.
  • Issue one token per device or user so access can be revoked individually without affecting the others.

Remember to store your API credentials securely and never share them publicly.