Skip to Main Content
Access Hospitality - Ideas Portal

Help us shape the future of our products by submitting your own ideas and reviewing ideas submitted by other users. If you see an idea you like, feel free to vote it up and add any comments that you feel would be beneficial.
This is a collaborative community, so please join in, contribute your innovative ideas and help our product teams to shape their roadmaps and future product development.

Our teams will review the ideas which have received the most votes on a regular basis, meaning that not all ideas will receive updates. When an idea has received enough votes, the status will be updated to 'Under Review' and then a decision made.

Status Idea Received
Product Access Maintain
Created by Guest
Created on May 18, 2026

Feature Request: Self-Service API Key Management for Contractors & Decoupled Permission Model for Aggregators

Summary: We currently lack a scalable and secure method for generating API keys for our external partners. This request outlines the need for a dedicated interface within the Contractor Module to allow self-serve API key generation, as well as a new, neutral method for provisioning API keys to third-party Aggregators without inheriting the creator's user permissions.

Current Behaviour / Problem Statement: This issue is currently two-fold and creates significant operational bottlenecks and security concerns:

  1. Contractor Limitation: Contractors currently do not have the ability to request or generate their own API keys within the Contractor Portal.

  2. Aggregator Limitation & Security Risk: Aggregators cannot request API keys because they do not exist on the portal as Contractors. Currently, the only way to generate an API key for an Aggregator assigns the key the exact same permissions as the internal user (Creator) who generated it. This violates the principle of least privilege and creates a security risk, as Aggregator keys should not be tied to an individual employee's permission set.

Proposed Solution / Requested Behaviour:

  • For Contractors: Introduce a self-service interface within the Contractor Module where authenticated Contractors can request, generate, and manage their own API keys securely.

  • For Aggregators: Develop a "Neutral" API Key Creation Interface. This should function like a service account, allowing internal admins to generate API keys for Aggregators with customised, scope-limited permissions that are entirely independent of the Creator’s personal user permissions.

  • Attach files
  • Guest
    May 20, 2026

    This gets my backing