Skip to main content

Service Accounts

Service accounts give you machine-to-machine access to Vendasta APIs, authenticated with a private key instead of a user login. Use them for system-to-system integrations that need to call Vendasta APIs without a person signing in.

API and access security

Vendasta maintains a current SOC 2® Type 2 report covering its security controls. For details on how automated access and API keys are secured, see Security and privacy or visit the Vendasta Trust Center.

Who can manage service accounts​

The Service Accounts tile under Administration → Advanced appears only for admins with the Can create and manage admins permission. That permission can be turned on only for admins whose market access is set to all markets. If you don't see the tile, ask an admin on your team who has this permission to update your access. See Permissions.

If the tile shows an upgrade icon, service accounts aren't included in your current subscription.

How to create a service account​

  1. Go to Partner Center → Administration → Advanced → Service Accounts.
  2. Click Create Account.
  3. On the Add Service Account page:
    • Optionally enter a Title to help you identify the account later.
    • Enter an Email ID. It must be at least 3 characters long and contain only lowercase letters, numbers, and hyphens. This becomes the account's identifier: <your-id>@partner-service-account.apigateway.co.
  4. Click Create.

How to generate a private key​

Creating a service account takes you to its Manage Keys page.

  1. Click Generate Private Key (ES256) or Generate Private Key (RS256), depending on which signing algorithm your integration requires.
  2. Use the generated key to authenticate your integration's API requests.

How scopes work​

Scopes control which APIs an access token can call, such as order:read to read sales orders. You don't assign scopes to a service account, and there's no scope setting in Partner Center. Your integration lists the scopes it needs each time it requests an access token from the service account's key.

To give your integration access to another API, add that API's scope to your integration's token request. Each endpoint in the API reference lists the scopes it accepts. For step-by-step instructions, see Obtaining an access token.

FAQs​

Can Vendasta Support add a scope to my service account?

No action from Vendasta is needed. Scopes aren't stored on the service account. Add the scope to your integration's token request, then request a new access token.

Why can't I see Service Accounts in Partner Center?

Your user needs the Can create and manage admins permission, which is available only to admins with access to all markets. Ask an admin on your team who has this permission to update your access.

If you need assistance with service accounts or have questions about automated access, contact our support team.