Skip to main content

API clients

To embed the widget or connect your own systems to Wiselook, you need an API client: a set of credentials your backend uses to talk to the Wiselook API. Admins create them under the Settings gear → API clients.

Getting access​

API clients are not enabled by default. Until they are, API clients doesn't appear in the Settings menu. To enable them for your organisation, contact us.

Creating a client​

  1. Under the Settings gear → API clients, create a new client and give it a name that says what it's for, e.g. Careers site widget.
  2. Choose its permissions (see below).
  3. Wiselook shows you the client's secret once. Copy it immediately and hand it to your developer through a secure channel; it can't be shown again.

A client only ever acts for your organisation. It can't see or change another organisation's data.

Choosing permissions​

A client's permissions decide what it can do. Pick them by what you're building, and grant only what that needs:

You're buildingSelect
Assessments on your own website (widget)Mint widget visitor sessions
Bulk invitations (guide)Create and revoke invite codes · List invite codes and usage · List adopted methodologies · List tags (if you group invites)
A sync with your HR or people system (guide)List your organisation's users · Update a user's name, role, status and tags · List tags
Assessments started from your own system (guide)Start an assessment for a member and run its conversation · Read an assessment and its result

Permissions are fixed when the client is created. If an integration later needs more, create a new client with the right permissions and revoke the old one.

In OAuth2 terms, each permission is a scope. Your developer will find the technical name of each one, and what it opens, in Authentication.

Rotating and revoking​

  • Rotate issues a new secret, and the old one stops working immediately. Your developer must update the integration with the new secret.
  • Revoke switches the client off for good. It can't be re-enabled; create a new client instead.

Rotate secrets on a schedule, and revoke a client at once if its secret may have leaked.