Skip to main content
Integration keys let an external system authenticate with Bold. External notifications notify other systems when an event occurs.

Integration keys

An integration key currently has broad administrative access to the tenant’s data and actions. You cannot assign it permissions or configurable scopes.
Anyone who obtains the key can act with elevated privileges on the tenant. Do not include it in client code, messages, public documentation or application logs.
Take these measures:
  • create a different key for each external system;
  • store it in a secrets manager;
  • limit who can view it in the system that uses it;
  • revoke it if it is no longer used or you suspect exposure;
  • coordinate key rotation with the integration.
The complete key is displayed when you create it. Keep a secure copy at that time.

External notifications

Use external notifications when another system needs to react to catalog, stock, order, manufacturing or maintenance changes.
For critical integrations, combine external notifications with periodic reconciliation through the API. Reconciliation lets you detect differences even if a delivery fails.