# API Token Authentication

**URL:** <https://developer.sailpoint.com/discuss/t/api-token-authentication/60182>\
**Category:** Connectivity Documentation Feedback\
**Tags:** va-con-docs\
**Created:** [June 2, 2024, 11:31am UTC](https://developer.sailpoint.com/discuss/t/api-token-authentication/60182 "2024-06-02T11:31:52Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![DocsTeam](https://avatars.discourse-cdn.com/v4/letter/d/ecd19e/32.png) [@DocsTeam](https://developer.sailpoint.com/discuss/u/DocsTeam)\
**Post date:** [June 2, 2024, 11:31am UTC](https://developer.sailpoint.com/discuss/t/api-token-authentication/60182/1 "2024-06-02T11:31:52Z")

</div>

The connector can authenticate with the source using an API&nbsp;token. The API token you provide is saved to the `accesstoken` attribute in the application configuration. API tokens are given in the following format:

* * *
This is the companion discussion topic for the documentation at [https://documentation.sailpoint.com/connectors/webservices/help/integrating\_webservices/api\_token\_authentication.html](https://documentation.sailpoint.com/connectors/webservices/help/integrating_webservices/api_token_authentication.html)

---

<div class="post-metadata">

**Author:** ![mdewallnc](https://avatars.discourse-cdn.com/v4/letter/m/e19b73/32.png) [@mdewallnc](https://developer.sailpoint.com/discuss/u/mdewallnc)\
**Post date:** [June 21, 2024, 9:08pm UTC](https://developer.sailpoint.com/discuss/t/api-token-authentication/60182/2 "2024-06-21T21:08:07Z")

</div>

How to use this token?

$application.apitoken$

???

---

<div class="post-metadata">

**Author:** ![ryan\_mccall](https://avatars.discourse-cdn.com/v4/letter/r/ac8455/32.png) [@ryan\_mccall](https://developer.sailpoint.com/discuss/u/ryan_mccall)\
**Post date:** [June 21, 2024, 9:22pm UTC](https://developer.sailpoint.com/discuss/t/api-token-authentication/60182/3 "2024-06-21T21:22:45Z")

</div>

Hi Matt! Thank you for your input. Can you provide more information to help our team understand how to best address it? Specifically, do you need more information on what the API Token field is used for or how to use that specific token?

---

<div class="post-metadata">

**Author:** ![mdewallnc](https://avatars.discourse-cdn.com/v4/letter/m/e19b73/32.png) [@mdewallnc](https://developer.sailpoint.com/discuss/u/mdewallnc)\
**Post date:** [June 21, 2024, 10:03pm UTC](https://developer.sailpoint.com/discuss/t/api-token-authentication/60182/4 "2024-06-21T22:03:04Z")

</div>

Hi Ryan, thanks for quick response. Seems related to this person’s thread:

> [@WebService source fails when using accesstoken variable in HTTP Operations header](https://developer.sailpoint.com/discuss/t/webservice-source-fails-when-using-accesstoken-variable-in-http-operations-header/17561/2):
>
> Hi @dmcconnell_epsilon, I don’t see any direct issues based on the description you posted. But here are few things I would try to get better insights on what went wrong, You can take a look at the VA log and revise the [log level](https://community.sailpoint.com/t5/IdentityNow-Articles/Enabling-Connector-Logging-in-IdentityNow/ta-p/188107) to print everything (DEBUG/TRACE) to see if it prints the entire request for further debugging. Try the curl alternative which practically does the same thing, curl --location --request POST '\<Your\_endpoint\>' \ --header 'x-api-key: $application.accesstoken$' \ --hea…

The documentation I’m citing, it doesn’t say how the API key it can be used, I think that would be helpful.

Later in the documentation, it does hint at how some of these tokens are used (HTTP Header Section) but there some other secrets are referenced, not the API token.

On top of everything, it doesn’t actually work (I had to use the cert secret password like the last poster mentioned), which makes it really frustrating, because even if you found the right name for that variable in the docs somewhere, it doesn’t actually work. So it seems to be compound issue of missing documentation and a bug on top of it.

At least on the page I’m mentioned, it should be stated somewhere, "this can be referenced in later connection setups as $application.whatever$, which can be placed into HTTP Headers, POST bodies, etc.

---

<div class="post-metadata">

**Author:** ![ryan\_mccall](https://avatars.discourse-cdn.com/v4/letter/r/ac8455/32.png) [@ryan\_mccall](https://developer.sailpoint.com/discuss/u/ryan_mccall)\
**Post date:** [July 5, 2024, 2:33pm UTC](https://developer.sailpoint.com/discuss/t/api-token-authentication/60182/6 "2024-07-05T14:33:16Z")

</div>

Hi Matt, thanks for the additional information. I’ve created CON-DOCS 4162 to track this change on our end. We’ll look into adding some additional information on this page around the API token variable and how/where it can be used.

---

<div class="post-metadata">

**Author:** ![joshb488](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/joshb488/32/11416_2.png) [@joshb488](https://developer.sailpoint.com/discuss/u/joshb488)\
**Post date:** [January 24, 2025, 3:39pm UTC](https://developer.sailpoint.com/discuss/t/api-token-authentication/60182/7 "2025-01-24T15:39:12Z")

</div>

Hi Matt! The work for CONDOCS-4162 has been completed, and the topic now contains more information about API token placeholders, as well as links to other parts of the guide with supporting information. I hope this helps.  
-Josh

---

<div class="post-metadata">

**Author:** ![joshb488](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/joshb488/32/11416_2.png) [@joshb488](https://developer.sailpoint.com/discuss/u/joshb488)\
**Post date:** [March 31, 2025, 12:49am UTC](https://developer.sailpoint.com/discuss/t/api-token-authentication/60182/9 "2025-03-31T00:49:56Z")

</div>

A post was split to a new topic: [Web Services in IIQ - Odd Test Connection Behavior](https://developer.sailpoint.com/discuss/t/web-services-in-iiq-odd-test-connection-behavior/105829)
