Filodos

API keys setup

For administrators: give your ERP or data warehouse its own read-only key, limited to exactly what it needs. Part of the documentation.

Create a key

  1. Sign in as an administrator and open Organization → API keys.
  2. Type a name, for example SoftOne feed.
  3. Tick the scopes the feed needs (see below).
  4. Click Create key. The key value shows once — copy it now. It never shows again.

Give the value to the person who builds the feed. It goes in the Authorization header as a bearer credential, the same place the dashboard puts its own sign-in token. The list shows only the key prefix afterwards, never the value.

Pick the scopes

Each scope opens one read family, for your own organization only. A key with no matching scope reads 403 on that endpoint. Keys never write anything.

  • devices:read — the fleet list.
  • trips:read — segmented trips per vehicle, plus one driver's trips.
  • events:read — driving events per vehicle, zone visits, plus one driver's events.
  • telemetry:read — black-box burst summaries and their per-second samples.
  • scores:read — stored vehicle score records.
  • drivers:read — driver rollups, driver lists, and assignment history.
  • positions:read — stored GPS fixes per vehicle.
  • reports:read — daily, weekly, and history summaries.
  • analytics:read — flat fleet-wide tables for BI tools: daily metrics, trips, events, zone visits, and vehicles.

A typical mileage feed needs devices:read and trips:read. A BI feed needs analytics:read. A visit-confirmation feed needs events:read too. Start narrow — you can create a wider key later.

Revoke a key

Click Revoke on the key row, then confirm. Feeds using it read 401 from that moment. The row stays in the list marked revoked, so the prefix remains recognizable. Revocation cannot be undone — create a new key if the feed still needs access.

If a key value leaks (a chat log, a screenshot, a shared file), revoke it at once and create a replacement. Only the hash is stored on our side, but the leaked value itself still works until revoked.