category image

I am a developer

REST API

Authentication and authorization

This article explains how Paazl authentication and authorization works. Paazl maximises the security of your webshop's order process by using three-legged OAuth 2.0 authentication in which the "API Secret" (private key) is only known to your webshop. Your customers can only access the "API Key" (public key).


Authentication & authorization overview


How the Paazl API authentication works is shown schematically in the following diagram.


How_it_works_-_authentication.png



Generating API keys


The Paazl web app's REST API configuration screen enables you to generate the public and private API keys that you need to request an access token from the Paazl authentication server.


To generate API keys, follow the steps below.


Note


If you do not see the "REST API" link referred to in step 3 below, contact Paazl Customer Support to activate it for you.


1a_Settings_1__new_.png


1b_Settings_1__new_.png


3_Generate_key_1.png


4_Generate_key_2.png



Token expiration


Access tokens are valid for 30 days from the moment they are returned by the Paazl authentication server.


The token retrieved at the start of a session is valid for the whole session, which means that, during the session, you can include it in subsequent API calls if you want to.


Whitelisting your webshop


In addition to working with an access token, you can whitelist the IP range of your webshop (and other sites) with Paazl. When you whitelist a site, you tell Paazl that you have explicitly authorized that site to request tokens. If you don't use whitelisting, any IP address can request tokens. We highly recommend that you use whitelisting.


To whitelist an IP range, log in to the Paazl web app and follow the steps below.


1a_Settings_1__new_.png


1b_Settings_1__new_.png


1_No_IP_addresses_message.png


2_Add_IP_address.png


3_edit-delete.png


Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article