API tokens and the REST API
Connect your own software or another service to Todah with a token. Free on every plan.
- Settings → Connected Apps → API Tokens. Give the token a name you will recognise, choose when it expires, and tick Allow changes only if it needs to create or edit records.
- Choose Create Token and copy it straight away. Todah keeps only a fingerprint and cannot show it again.
- Send it with every request as Authorization: Bearer followed by the token. The address and every endpoint are listed at todah.ca/developers.
A token acts as you and follows the same rules as the app: your role, your plan's limits, and each record's own rules. Nothing can be deleted through the API, and bank data, refunds, settings, team and billing are not part of it. Up to 60 requests a minute per workspace.
Revoke a token in Settings → Connected Apps as soon as you stop using it or think someone else may have it. Owners and admins see and can revoke everyone's tokens and connected apps.
Was this helpful?
Still stuck? Write to us or email support@todah.ca — a person replies, usually within a working day. The FAQ covers plans, prices and the questions people ask before they sign up.