Core CRM security hardening

Manage API-token expiry, revocation, rotation and usage metadata

Follow this guide to use the complete API-token lifecycle added by the security release. The guide then takes you through the correct route, the checks to complete before making changes, the workflow in order, and the evidence to review afterwards.

Audience: Administrators and deployment engineersPermission: Core release / deployment authority
Jump to steps
Where to goAutomatic core protection — no separate staff menu route

What you’ll accomplish

Use the complete API-token lifecycle added by the security release. The workflow below follows the supported application or module flow and does not invent a menu or bypass validation.

Follow these steps

  1. Use the supported Britixo CRM release or workflow that produces this security control.
  2. Check the expected protection through an authorised test.
  3. Record the result in the deployment or security audit evidence.

Fields and options to review

  • Expiry
  • Revoked state
  • Rotation relationship
  • Last-used metadata
  • Usage metadata

Rules the system enforces

  • Set and monitor token expiry.
  • Revoke a compromised or retired token.
  • Rotate by issuing a new token and retiring the prior one according to the authorised overlap policy.
  • Check last-used and other usage metadata for attribution.

How to confirm it worked

  • The protection is active without weakening another security control.

Security, audit and troubleshooting checks

  • Use the exact authorised account, role and record before saving or sending.
  • Verify the saved status and downstream record; a browser success message alone is not sufficient evidence.
  • Never expose passwords, API keys, access tokens, protected attachments or raw server paths in support tickets.
  • Do not edit module or core database records directly to bypass validation, permissions, migrations or state rules.

Connected discovery, service and API guides