Manage API credential and connection access

View as Markdown

API connectors enable you to configure a Call API action in a workbook. After you configure API connectors and credentials, you can manage user and team access to them. This document covers the permissions required for several common use cases involving API actions, as well as how to:

User requirements

  • To view all API connectors in an organization, you must be assigned an account type with at least one of the Manage API connectors, Create API actions, or Trigger API actions permissions enabled.
  • To request access to an API connector, you must be assigned an account type with at least one of the Manage API connectors, Create API actions, or Trigger API actions permissions enabled.
  • To approve or deny access requests for an API connector, you must be the owner of the connector, an admin, or a user with the Manage API connectors account type permission enabled and Can edit access to that specific API connector.
  • To manage API connector and credential access, you must be an admin, the owner of the connector or credential, or a user with the Manage API connectors account type permission enabled and Can edit access to that specific API connector/credential.

About granting access to API connectors

There are several ways users can access API connectors:

Admins or users with appropriate permissions enabled can also edit API credentials to provide users and teams with access to the credential.

API connector and credential access matrix

The following table details the minimum document access and account, connector, and credential permissions required for several common use cases involving API actions. For example, to trigger an action sequence with a Call API action, a user must have Can view access to the workbook with the action sequence, an account type with the Trigger API actions permission enabled, and Can use access to the connector.

Use caseDocument permissionAccount permissionConnector permissionCredential permission

Trigger an action sequence with a Call API action

Can viewTrigger API actionsCan useNone

Edit a Call API action

Can exploreCreate API actionsCan useNone

Create a Call API action

Can exploreCreate API actionsCan useNone

View details of an API credential

NoneManage API connectorsNoneCan use

View details of an API connector

NoneManage API connectorsCan useNone

Edit an API connector

NoneManage API connectorsCan editCan use1

Edit an API credential

NoneManage API connectorsNoneCan edit

Create a new API connector

NoneManage API connectorsNoneCan use1

Create a new API credential

NoneManage API connectorsNoneNone

1To manage the use of the credential in a connector, Can use access to the credential is required. However, Can use access to the credential is not required to edit other details of a connector.

View organization API connectors

To view all API connectors in your organization:

  1. From the Sigma header, select your user avatar to open the user menu, then select Profile.
  2. From the side panel, select API connectors. A list of all API connectors you have access to is displayed. Only the Name and Description of each connector are displayed.
  3. (Optional) To see API connectors you do not have access to, clear the Can use filter in the search bar, and select the No access filter instead. Any connectors you do not have access to appear in gray text. You can request access to API connectors.

Admins can access all listed API connectors.

  1. (Optional) For users with the Manage API connectors permission enabled, select Manage API connectors to view and edit full API connector details.

Request access to an API connector

To request access to an API connector:

  1. From the Sigma header, select your user avatar to open the user menu, then select Profile.
  2. From the side panel, select API connectors.
  3. Select Filters and select the No access filter to view API connectors you do not have access to.
  4. On your desired API connector, select More, then select Request access. When your request is sent, a confirmation message is shown.

An admin or the owner of the API connector can approve or deny the request.

Approve or deny an API connector access request

There are several ways to approve or deny an API connector access request:

From notifications in Sigma

If you are the owner of an API connector and a user requests access to that connector, you receive a notification in Sigma. To approve or deny the request:

  1. From the Sigma header, select Notifications.
  2. On the access request, select Approve or Deny. Approving an access request grants the user Can use access to the connector. To grant a different level of access, approve the access request from the Administration portal or from the email notification.

From an email notification

If you are the owner of an API connector and a user requests access to that connector, you receive an email notifying you of the request. To approve or deny the request:

  • From the email, select Respond to request. The Grant access modal opens in Sigma:
    • To approve the request, from the dropdown, select your desired access level for the user, then select Approve.
    • To deny the request, select Deny.

From the Administration portal

Even if you are not the owner of a specific API connector, organization admins or users with Can edit access to that specific API connector can approve or deny access requests from the Administration portal:

  1. Go to Administration > API connectors.
  2. Select the Connectors tab.
  3. Select the connector you want to approve or deny an access request for.
  4. Select + Grant access.
  5. In the Grant access to modal, you can view and respond to pending access requests:
    • To approve a request, from the dropdown, select your desired access level for the user, then select Approve.
    • To deny a request, select Deny.

Grant access to an API connector

You can grant access to an API connector without users having to request access by editing the API connector access in the Administration portal.

To grant users and teams access to an API connector:

  1. Go to Administration > API connectors:
    1. From the Sigma header, select your user avatar to open the user menu.
    2. Select Administration to open the Administration portal.
    3. From the side panel, select API connectors.
  2. Select the Connectors tab.
  3. Select the connector you want to manage.
  4. Select + Grant access.
  5. In the Grant access to modal, search for and select the users or teams to grant access to.
  6. Under Access, select the access to grant to each user or team.
  7. (Optional) To notify users when granting access, select the Send email checkbox.
  8. (Optional) If you checked the Send email checkbox, enter a message in the Add a message field.
  9. (Optional) To provide users with Can edit permission on that API connector with automatic Can use access on the associated API credential, turn on the Grant ‘Can edit’ users to have ‘Can use’ access to credentials toggle.
  10. Select Share.

Grant access to API credentials

To grant users and teams access to an API credential:

  1. Go to Administration > API connectors:
    1. From the Sigma header, select your user avatar to open the user menu.
    2. Select Administration to open the Administration portal.
    3. From the side panel, select API connectors.
  2. Select the Credentials tab.
  3. Select the credential you want to manage.
  4. Select + Grant access.
  5. In the Grant access to modal, search for and select the users or teams to grant access to.
  6. Under Access, select the access to grant to each user or team.
  7. (Optional) To notify users when granting access, select the Send email checkbox.
  8. (Optional) If you checked the Send email checkbox, enter a message in the Add a message field.
  9. Click Share.