How to use the API and access tokens
The Rabbiit API lets another system read and write account data — reports, time entries, projects — on behalf of a user. Each integration uses an access token. Whoever has the token operates with the same permission level as that person.
This is different from a webhook: you call the API when you need it; Rabbiit fires the webhook on its own when the event happens.
💡 Plan: the Integrations panel (usage, account tokens, and creation permission) is part of Ultimate. Each plan has a daily request limit. Endpoint documentation is at api-docs.rabbiit.com.
Who it is for
Personal API tokens screen
Administrator — follows usage, sets who can create a token, and revokes access when someone leaves or a vendor stops providing the service.
Whoever integrates (admin, superuser, or member, depending on the configuration) — generates their own token under My Tokens and stores it in the integration vault.
Team member without token permission — does not create a key. Continues only logging hours.
Where to find it
There are two screens:
- Settings > Integrations — the administrator sees API usage, who can create tokens, and the list of account tokens.
- You > My Tokens — each authorized person creates and revokes their tokens.
The two coexist: creation is personal; the account view is the administrator’s.
API management
API management with daily request usage
Under Settings > Integrations, API management tab:
- Daily API usage — progress bar with how many requests have already been made and how many remain.
- The limit is shared across all tokens on the account. It is not a cap per person.
- The panel shows when the limit renews.
- There is a limit. If the account hits the plan cap, calls are refused until renewal — or until an upgrade.
On the same tab the administrator sets who can create personal tokens:
- Administrators only
- Administrators and superusers
- All members
Only the administrator changes this setting. Anyone outside the chosen group does not see My Tokens (or cannot create).
My Tokens
Each authorized person opens You > My Tokens and creates their own keys.
- Click New token.
- Give a name that identifies the destination (“Client X ERP”, “Report script”).
- On create, the token value appears once. Copy it and store it in the integration vault; it is not shown in full again.
- Whoever has the token has the same access as your user on the API. Do not share the same key with everyone — one token per integration.
- Revoke as soon as the access is no longer needed (project ended, tool changed, you left that operation).
The list shows name, token ending (to check against what you stored), creation date, and last access.
Account tokens (administrator)
Under Settings > Integrations, Account tokens tab, the administrator sees the active personal tokens of each person: owner, name, token ending, creation, and last access.
From there you can revoke anyone’s token. The integration that used that key stops authenticating at once. Use it when the person left, a vendor ended, or a key leaked.
The administrator does not create the token “for” the other person on this tab — each person generates theirs under My Tokens. Here the role is visibility and revocation.
When to use the API (and when the webhook)
Use the API when the other system pulls a report, syncs a catalog, or writes a time entry on demand.
Use a webhook when the other system needs to react at the moment of the event (hour logged, week approved, project created).
If the account does not integrate with anything, ignore these screens. Reports and the timesheet cover day-to-day work without a token.