API Authentication
How dashboard login and the widget embed token work — no developer API key system.
The page “API Authentication in Zentor App” covers the function identified by this URL. The existing summary is expanded with the actual workflow, prerequisites and known limitations. Zentor has no developer API-key system. The dashboard uses session JWTs with a 12-hour lifetime and refresh tokens lasting seven days; TOTP and SSO are optional. Widget embed tokens are shown in plaintext only once and are restricted to approved origins.
Zentor has no general developer API-key system. Dashboard access uses session JWTs valid for 12 hours and refresh tokens valid for seven days, with optional TOTP and SSO.
The Widget applies an embed token shown in plaintext only once. Access is also restricted by the approved origin, so a token alone is not sufficient from an unapproved website.
JWTs and Widget tokens must never be committed to repositories or included in public logs and examples. Expired credentials must be replaced through the intended login or refresh flow.
Internal dashboard and Master Admin routes are not a public developer interface. Authorisation remains limited by role and active tenant.
For “API Authentication in Zentor App”, the expanded text is required to remain specific to https://zentor-app.de/en/hilfe/api-authentifizierung, use only verified facts and clearly separate tenant self-service from actions performed by Zentor. Any support case needs to identify this exact page, the active tenant and the observed step without disclosing credentials.
This page also explains its role within the Help Center, from the first check to the expected result, while naming verified limitations and the relevant detailed area. Statements that are not supported for https://zentor-app.de/en/hilfe/api-authentifizierung are not added. The expansion is therefore substantial without importing unrelated features or repeating generic filler.
When using “API Authentication in Zentor App”, test one controlled scenario at a time and compare the visible setting, the actual system status and the expected result. If the outcome differs, record the exact time, tenant, channel and unchanged error message. Screenshots and support notes must exclude passwords, tokens and unnecessary personal data so that troubleshooting remains both useful and safe.