Create an account dedicated to API usage
Every integration with the Certificall API (creating files from your software, uploading documents, tracking consumption, Certilink buttons…) authenticates with a username and password, exactly like a person does. Instead of reusing an employee's credentials, create an account dedicated to the API: a technical user, with no other purpose, holding only the rights your integration needs.
This guide explains how to create that account from the admin interface, set its password, choose its rights, and hand the credentials over to your technical team without exposing them.
- Continuity: if the employee leaves the company or changes their password, your integration keeps working.
- Least privilege: the account only carries the API rights it needs, nothing more.
- Traceability: files created by the integration are attached to this account, not to a person.
- Easy revocation: if in doubt, you change its password or delete the account without affecting anyone.
Prerequisites
| Prerequisite | Details |
|---|---|
| Access to the admin interface | admin.certificall.app, with a Manager or Reseller role that is allowed to create users. See Roles on the admin interface. |
| API rights on your own account | You can only delegate rights you hold yourself. If the API section does not appear among the permissions in step 4, ask your Certificall contact to enable API rights for your company. |
| A dedicated e-mail address | The e-mail address is used as the username and must be unique across Certificall. Plan a technical address (for example api@your-company.com) or an alias (firstname.lastname+api@your-company.com). |
Step 1 — Open your company's user list
- Log in at admin.certificall.app.
- Open your company page, then the Users tab.
- Click Add a user. The Create a user panel opens on the right.

If you manage subsidiary companies, open the relevant company page first: the API account is created in the company the files should be attached to.
Step 2 — Fill in the account information
In the Informations section:
- First name / Last name: choose values that clearly identify the purpose, for example
API/ERP integrationorAPI/Website. This label is what appears in the user list and on files created by the integration. - Email: the technical address chosen above. It becomes the username your integration will send to the API to authenticate.
An e-mail address can only be linked to a single account. If you create several API accounts (one per environment, one per software…), use a different address or alias for each of them.
Step 3 — Set the password
In the Password section:
- Click Generate a password: Certificall fills both the Password and Password confirmation fields with a strong random value. This is the recommended method for a technical account: nobody has to remember it.
- Click Copy generated password and paste it immediately into your password manager (see step 5). The password can no longer be viewed once the account is saved.
If you prefer to type your own password, it must follow these rules:
- at least 6 characters (aim for far more on a technical account: 20 characters or more);
- at least one uppercase letter, one lowercase letter and one digit;
- no spaces.

An API account's password is stored in your software's configuration. It must be unique, randomly generated, and never used anywhere else.
Step 4 — Choose the role and rights
In the Role section:
- Select the Manager role. This is the role that reveals the Permissions block; the App user role only grants access to the mobile application and is not suitable for API usage.
- In the Permissions block, expand the API section and tick only the rights your integration needs.
- Leave every right in the Administration interface section unticked: an API account has no reason to log into the admin interface.
Which API rights should you tick?
| Section | Right | Tick it if your integration… |
|---|---|---|
| File | Create | creates files, uploads documents to a Document upload step, closes files. This is the minimum right for almost every workflow. |
| File | Consult | reads the content or status of files, downloads PDFs. |
| File | Update | modifies an existing file (metadata, report reference…). |
| File | Delete | deletes files. Grant it only when there is a proven need. |
| Item | Create | uploads photos, videos or signatures itself into a file. Not needed for a simple document upload. |
| Certilink | Create / Consult / Update / Delete | generates or manages Certilinks (capture links sent to your customers or embedded in your screens). |
| Template | Consult | lists the available templates to retrieve a frameId. |
| Template | Create / Update / Delete | administers templates through the API. Reserved for advanced integrations. |
To know exactly which right each endpoint requires, refer to the developer documentation: File management, Item management, Certilink.

Some rights cannot be ticked in this form and are granted by your Certificall contact, for example the consumption tracking right described in Track your consumption. If an endpoint answers 403 although the account is correctly configured, one of these rights is probably missing.
Finally, click Save. The account appears in the user list with the Enabled status.
Step 5 — Share the credentials securely
The account has just been created and you are the only person who knows its password. You now need to hand it over to the team that develops or operates the integration, without it lingering afterwards in a mailbox or a chat.
Do
- Use a company password manager (Bitwarden, 1Password, KeePass, Vaultwarden, Dashlane…): create the entry in a vault shared only with the people involved. This is the preferred method: the secret stays encrypted, access can be revoked and history is tracked.
- Otherwise, use a one-time link that self-destructs after being read or after a short delay (Bitwarden "Send", Password Pusher, One-Time Secret, or the equivalent tool approved by your IT department).
- Split the channels: if you still have to communicate the secret directly, send the username through one channel and the password through another (e-mail followed by a phone call, for instance), and never in the same message.
- On the integration side, ask that the credentials be stored in a secrets manager or in the hosting platform's environment variables, never in source code or a versioned file.
Don't
- Send the password in clear text by e-mail, SMS or instant messaging (Teams, Slack, WhatsApp…), even to a single person, even "just this once".
- Paste it into a ticket, a shared document, a wiki, a code comment or a Git repository.
- Reuse the API account to log into the admin interface or the mobile application.
- Share the same API account between several pieces of software or several providers: create one account per integration, so you can revoke one without stopping the others.
Check that the account works
Once the credentials have been handed over, the technical team can verify the account right away by requesting a token:
curl -X POST https://admin.certificall.app/certificall/api/auth/token \
-H "Content-Type: application/json" \
-d '{ "username": "api@your-company.com", "password": "the_generated_password" }'
A 200 response containing a token confirms that the account is active. Authentication is described in detail in Public authentication.
Day to day: maintaining the account
- Change the password: open the Users tab, click Edit user, then enter a new password (and its confirmation) in the Password section. Use your password manager to generate one. Remember to update the integration's configuration at the same time, then replace the entry in your password manager.
- When to rotate: when someone who knew the secret leaves, when you change provider, at the slightest suspicion of a leak, and on a planned basis (for example once a year).
- Adjust the rights: from Edit user, Role section, tick or untick the API permissions as your integration evolves. The change applies immediately to new tokens.
- Decommission: when an integration is retired, delete the account with Delete user, or at least change its password without sharing it.
Summary
- Users → Add a user on your company page.
- Explicit first name / last name, dedicated technical e-mail (it will be the
username). - Generate a password, copy it and store it safely right away.
- Manager role, API section only, rights kept to the strict minimum.
- Hand the credentials over through a shared vault or a one-time link, never in clear text.