---
title: "WorkBook API > User Permissions"
canonical: "https://technology.bytangram.com/space/TGKB/769916998/WorkBook%20API%20%3E%20User%20Permissions"
format: markdown
---
In WorkBook, there are two levels of access controls that affect API requests. Since the WorkBook interface uses the API, having access to a view means that the user has access to the underlying API calls.

> 📝 We recommend having a user specifically for API integration purposes

| **ON THIS PAGE YOU WILL FIND:** |
| --- |
| > Macro (toc) |

---

## SETTING UP AN API USER ROLE

We recommend that you spend some time in the following WorkBook interface to learn and understand how to set up users correctly, specifically while working with API calls.

To set up an API user:

- Navigate to **settings **> **advanced tools **> **user access rights **
- Click the **add a new access role** icon > make sure the check mark is set to **API only** (as shown below)

![image](media://fc3948f6-5422-4349-b3aa-43a1ddc4234e)

> ℹ️ Next you will need to either assign this access role to an employee or create a new employee and assign them to this access role. See adding new employees [here](https://technology.bytangram.com/space/TGKB/1414234246/Resources+%3E+Create+an+Employee).

---

## API ACCESS ROLE REQUESTS

- Go to the **access role requests** > this tab will list all **API calls** within WorkBook
- Scroll/search and select the **required calls** for your specific needs

> ℹ️ If you’re in doubt, check the [https://tangram.atlassian.net/wiki/spaces/TGKB/pages/769884204/WorkBook+API+Authentication#HOW-DO-I-FIND-THE-CALLS-NEEDED%3F](https://tangram.atlassian.net/wiki/spaces/TGKB/pages/769884204/WorkBook+API+Authentication#HOW-DO-I-FIND-THE-CALLS-NEEDED%3F) article on how to retrieve API calls

![image](media://04b25cca-3bb8-497e-a4e1-766ad0190aea)


> ⚠️ Important: the pencil icon on the request line means that it has <u>NOT</u> applied the change. To commit the change either press enter or click elsewhere in the interface to complete the action

---

## COMPANY ACCESS

Once created, the API User will require the correct company access, if you’re working with multi-company or finance data that needs to be extracted.

To give company access go to:

- The **resources** module >** employee settings grid** > select the** API user** from the list
- Open the **user card** > go to the **settings **tab > **login settings **> select the **company access** tab
- Go to the **company/s** the API user will need access to > **check the boxes** of the area/s required for access according to the API calls enabled

![image](media://ab5306d1-cb15-48f7-98b0-4470bd183750)


## USING AN API KEY

The API Key must be passed with the Request Headers.  
  
<u>**Example:**</u>  
  
URL:   
https:{{domain}}.workbook.net/api/{{endpoint}}  
  
Headers:  
Authorization: Bearer {{API KEY}}



---

#### Related articles

> Macro (contentbylabel)