Public vs Private Integrations
Understand when to use public or private Bokio integrations and how each authentication model works.
Choose a private integration for one Bokio company, or a public integration for an application that multiple companies can use.
- Use a private integration for an integration that serves one company.
- Use a public integration for an integration that serves multiple companies, such as a CRM, commerce system, or integration platform.
Key differences
| Feature | Public integrations | Private integrations |
|---|---|---|
| Availability | Available to multiple companies | Specific to one company |
| Usage limit | No limit on the number of companies | One company |
| Company API price plan | The company's price plan must include the Integrations (API) feature. See price plans for details. | Included in Premium, Business, and Plus plans, with a limit of 5,000 requests per month. |
| Authentication | OAuth 2.0 | Integration Token from the Bokio app |
| Available APIs | General API and Company API | Company API |
Private Integrations
Use a private integration to connect one company's internal systems or processes to Bokio. Create the integration in the Bokio app and authenticate requests with an Integration Token (a token that authorizes access to the company's data).
A company can create multiple private integrations and assign each integration only the permissions it needs. This helps limit access for company-specific workflows.
How Private Integrations Work in Bokio
Integration Token
Create a private integration in the Bokio app to generate its Integration Token. Use this token to authenticate API requests and authorize the application to access the company's data.
Custom Use Cases
Build private integrations for company-specific needs, such as automating data entry, synchronizing financial records with another system, or generating custom reports.
Example Workflow
- Generate an Integration Token: Create a private integration in the Bokio app.
- Configure authentication: Configure the integration to use its Integration Token.
- Access company data: Use the token to make authenticated API requests to Bokio.
Public Integrations
Use a public integration for an application that multiple companies can connect to, such as a CRM, commerce system, or integration platform. Public integrations can access the General API and Company API, although some access may require additional permissions.
Register public integrations in the Developer Portal. See Create and edit an application in the Developer Portal.
Public integrations use OAuth 2.0 for authorization. Each API uses a different OAuth 2.0 grant:
- General API: Client credentials grant
- Company API: Authorization code grant
How Public Integrations Work in Bokio
Developer Portal
Register your application in the Bokio Developer Portal. Provide its name, description, and required permissions. For details, see Create and edit an application in the Developer Portal.
Security through OAuth
OAuth is a standard authorization protocol that lets third-party applications access data without receiving the user's Bokio credentials. When a user connects their Bokio account, Bokio asks them to sign in and authorize the application.
The OAuth flow has these steps:
- Send an authorization request: Redirect the user to Bokio's authorization endpoint.
- Request consent: The user signs in to Bokio and grants the application permission.
- Receive an authorization code: Bokio redirects the user to your application with an authorization code.
- Exchange the code: Your application sends the authorization code to Bokio's token endpoint and receives an access token.
- Make authenticated requests: Use the access token to call Bokio APIs on the user's behalf.
No Limitation on Usage
After you register a public integration, multiple companies can connect their Bokio companies to your application.
Example Workflow
- Register your application: Register the application in the Bokio Developer Portal and obtain its Client ID and Client Secret.
- Request OAuth authorization: Redirect the user to Bokio's OAuth authorization URL. After the user signs in and grants permission, Bokio redirects them back to your application with an authorization code.
- Exchange the authorization code: Send the code to Bokio's token endpoint to receive an access token.
- Access data: Use the access token to make authenticated requests to Bokio's API on the user's behalf.
For details, see Getting started with Public Integrations.
Updated about 1 month ago

