Client Portal API profiles and one-time tokens

Allow portal section: Automatic enabled module data

Data from detected supported modules. The guide then takes you through the correct route, the checks to complete before making changes, the workflow in order, and the evidence to review afterwards.

Audience: CRM administrators, integration developers, external portal backend teams and security reviewersPermission: AdministratorModule v1.0.0
Jump to steps
Where to goAdmin Area → Utilities/Tools → API Gateway → Create Client Portal API
Before you start
  • Verify the module is active and use the exact navigation shown above.
  • Use an account with the stated module and core CRM permissions.
  • Use known test records when changing statuses, visibility, saved filters or global navigation.

What you’ll accomplish

Data from detected supported modules. The instructions below follow the supplied module’s live menu, controller, form, model and JavaScript flow.

Follow these steps

  1. Go to Admin Area → Utilities/Tools → API Gateway → Create Client Portal API.
  2. Find the record, endpoint, field or action used to allow portal section: automatic enabled module data.
  3. Complete the displayed values exactly as described in this guide.
  4. Select the available save, submit, send, upload, create, update or confirm action.
  5. Return to the related register, portal, activity log or API response and verify the expected result.

Fields and options to review

Allowed sectionAutomatic enabled module data
PurposeData from detected supported modules.

Rules the system enforces

  • The external session can retrieve the section only when the profile includes its key and the client identity owns the related records.

How to confirm it worked

  • The allow portal section: automatic enabled module data workflow completes without a validation, permission, ownership or availability error.
  • The related record, portal view, activity entry, notification log or API response shows the expected state.
  • Client-visible, public and API data remains limited to the code-backed ownership and visibility rules.

Security, privacy and operational checks

  • Use controlled test records and non-production credentials before wider rollout.
  • Grant least privilege and protect secure links, personal data, uploaded files, signatures, API tokens, allowed origins and server IPs.