Authorization header. For a server that works with your own sajn workspace, that token is an API key, which this page covers.
If you build software that other sajn customers connect to their own accounts, use OAuth 2.0 instead. If you’re not sure which applies to you, see Choosing an authentication method.
Create an API key
To create a key, you need the Hantera API-nycklar permission in the workspace, and the organization needs API access. API access is included from the Team plan, and in every sandbox.- In the sajn app, open the workspace that the integration works in.
- Go to Inställningar > Utvecklare > API-nycklar. Utvecklare is in the workspace settings.
- Click Skapa API-nyckel.
- Enter a name that says what uses the key, such as
crm-sync-production. - In Utgår, choose when the key expires: after 30 days, 90 days, 1 year, or never.
- Click Skapa nyckel, and copy the key. sajn shows the full key only once.
Key prefixes
The prefix tells you which kind of organization a key belongs to:
Both kinds use the same base URL. The key decides which environment the request reaches.
Send the key
Send the key as a bearer token in theAuthorization header, together with the API version:
SAJN_API_KEY environment variable.
What a key can do
A key is bound to the workspace you created it in, and acts as the user who created it:- One workspace. Every request works on that workspace’s documents, contacts, and templates. You never send a workspace ID. If your organization has several workspaces, create one key per workspace.
- The creator’s role. The key can do what the creator’s workspace role allows, and nothing more. If the role changes, so does what the key can do. A request that the role doesn’t allow fails with the code
PERMISSION_DENIED. - No scopes. Unlike an OAuth token, an API key isn’t limited to a set of scopes.
ACCOUNT_INACTIVE. To keep an integration running when people change roles or leave, we recommend creating its keys from an account that exists only for the integration.
To check which user, workspace, and organization a key acts as, call GET /me:
Rotate a key
To replace a key without downtime, do the following:- Create a new key, as described in Create an API key.
- Deploy the new key to your integration.
- Confirm in the Senast använd column of the API key list that the old key is no longer used.
- Delete the old key.
Keep keys safe
Keep keys out of code
Keep keys out of code
Store keys in environment variables or a secrets manager. Never commit a key to version control, and never send it to a browser or a mobile app.
Use one key per integration and environment
Use one key per integration and environment
A separate key for each integration and environment limits what a leaked key exposes, and lets you revoke one without breaking the others. Use a sandbox key for development and testing.
Set an expiration date
Set an expiration date
A key that expires limits how long a leaked key works. Rotate it before it expires.
Review key usage
Review key usage
The API key list shows when each key was last used. Delete keys you no longer use. To see individual requests, use the API logs under Inställningar > Utvecklare > Loggar.
Authentication errors
A failed authentication returns an error in the standard shape. Branch oncode, not on message, show userMessage to your users, and log requestId:
In API version
2026-09, the error body has no requestId, and the code values differ. For every error code, see Errors. For the request limits per organization, see Rate limits and quotas.
