C2 Overview
API Integrations
Create and revoke community API clients without exposing their credentials.
An integration client lets an external application act with one selected C2 role. Treat it like a staff credential: choose the smallest role that works and remove it when the integration no longer needs access.
Before you start
- You need
admin:manage-community. - Your community needs the
community_api_accessfeature. - Create or identify a role whose permissions are limited to the integration’s job. C2 loads roles from the community roles API.
- Have a secure secret store ready before creating the client.
Create a client
- Open Settings > API Integrations and select Create client.
- Enter a meaningful Client name.
- Search and select exactly one Role.
- Select Create client.
- In Client credentials generated, copy the Client ID and Client secret into the integration and secure storage before closing the dialog.
- Select View clients to return to the list.
| Control | Prerequisite | Result | Risk |
|---|---|---|---|
| Client name | Non-blank value | Labels the client in C2. | A vague name makes emergency revocation harder. |
| Role search / role card | At least one available community role | Selects the permissions the client receives. | Over-privileged roles give the external system unnecessary community access. |
| Create client | Name, role, permission, and community_api_access feature | Creates the client and reveals the secret. | The secret is shown once; do not put it in a ticket, chat, or source control. |
| Copy secret | Browser clipboard permission | Copies the one-time secret. | Clear the clipboard or use a password manager after storing it. |
| Delete | admin:manage-community and confirmation | Revokes that client. | Destructive: the connected application immediately loses authentication. Remove its credentials/configuration too. |
Manage clients
The list shows each client’s name, assigned role, client ID, active status, and creation time. Use Delete only after you have identified the dependent bot or service; C2 offers no rotation control on this page. If a secret may have leaked, delete the client promptly and create a replacement rather than waiting for routine maintenance.
Failure handling
| Response or symptom | Meaning | Action |
|---|---|---|
| Client creation unavailable / 402 | The feature is not available to the community. | Ask an owner to review the plan/feature; changing role permissions will not enable it. |
| 403 | Active profile lacks admin:manage-community. | Use an appropriately authorised staff profile. |
| No roles shown | There are no accessible community roles or the roles request failed. | Create/verify a role before creating the client. |
| Secret dialog closed before storage | C2 does not expose a recovery control. | Revoke the client and create a new one if the secret is required. |