Creating and revoking API tokens
A personal token lets another system use Tario's API with your user and the permissions you give it; it is created under API Tokens, shown once and revoked with your password.
If you are not signed in, Tario asks you to log in and opens your current company.
Steps
Open the user menu → API Tokens and click New token.
Type the Token name (for example, the system that will use it) and pick the minimum Permissions: Read, Create, Update or Delete. Confirm with Create token.
Copy this token now appears: use Copy token and store it in the other system; it is not shown again.
The system sends it in the
Authorization: Bearer <token>header. If you belong to several companies, say which one withX-Tario-Company: <id>; the token only sees companies you are a member of and respects your module permissions.The list shows Permissions, Last used and Created. Edit token changes its permissions; Revoke disables it immediately after you enter your Current password.
The API documentation link opens the full endpoint reference.
Tips
- Each token allows 120 requests per minute; if an integration needs more, use webhooks instead of polling.
- Create one token per integration: if one is compromised, you revoke only that one.
Common errors
| Code or message | What it means | How to fix it |
|---|---|---|
This token does not have the ability required for this action. | The token lacks the permission (for example Create) the endpoint requires. | Use Edit token and add the permission, or create a new one. |
This token is not authorized for the requested company. | X-Tario-Company points to a company you are not a member of or the token is not bound to. | Check the company id in the header. |
Ask Tario AI
Opens the assistant inside Tario with the question typed, ready to send.
Ask Tario AI