Issue a token that acts as a teammate
Let a back-office system call the API as a specific member of your account.
Open this guide in the help center →
When to use this. An internal system needs to act in Formbot as a named colleague rather than as a shared account.
What you’ll need. Owner or admin access, and the member you are delegating as.
Understand what it is for
A delegated token acts as one named member, pinned to one account. Use it when an internal system must create or read work that belongs to a particular person, rather than appearing as a shared robot with no owner.
Check you are allowed to issue one
Only an owner or admin can mint a delegated token, and only for a member of their own account. This is a privileged action: the token can do what that member can do.
Issue the token
Call the delegate-token endpoint for the user you are delegating as, and record a reason. The reason is what makes the audit trail readable months later.
Store it like a password
Put it straight into your server's secret store. Never commit it, never send it to a browser, and never paste it into a ticket.
Revoke it explicitly when finished
List your delegations and delete the one you are done with. Revoking is the reliable control — do not depend on the recorded expiry to end access for you, and revoke immediately if the member changes role or leaves.
Confirm it acts as the right person
Make one read call and check the identity that comes back is the member you intended, in the account you intended.
How to know it worked
Your system authenticates as the intended member, and you can revoke that access in one call.
Features covered
- Delegated account tokens
- REST API
- Audit trail