# API access

> Call the Integration Service API from an external application, using OAuth 2.0 authorization and Integration Service scopes.

## Overview

The Integration Service API lets you work with Integration Service resources from an external application of your choice. You authorize the application through the OAuth 2.0 framework, so a service or script can authenticate on its own instead of relying on a signed-in user session, and without sharing any credentials.

Use it to call Integration Service from a CI/CD pipeline that publishes or deploys a solution referencing a custom connector, or from a coded app or agent that needs to create or manage its own Integration Service connections without a signed-in user.

Access is confined to the scopes you grant. An external application, or a user acting through one, cannot exceed those permissions. Existing API access using user tokens is unchanged.

Learn how to [register an external application](https://docs.uipath.com/automation-cloud/automation-cloud/latest/admin-guide/managing-external-applications).

## API permissions

To call the Integration Service API, you must grant API permissions to the external application. These permissions are known as scopes. Add them in Automation Cloud under **Admin > External Applications**, by adding **Integration Service** as a resource.

| Scope | Grants | Available as |
| --- | --- | --- |
| **IS.Connections.Read** | Read access to connections. | User scope |
| **IS.Connectors.Read** | Read access to connectors, including downloading a custom connector. | User scope, application scope |
| **IS.Connector.Export** | Not used. No endpoint requires this scope. | N/A |

:::important
**IS.Connections.Read** is a user scope only. An external application that authenticates on its own, without a signed-in user, cannot be granted it.
:::

Non-confidential applications can be granted user scopes only. For the difference between the application types and between user and application scopes, see [Authorizing external applications](https://docs.uipath.com/automation-cloud/automation-cloud/latest/admin-guide/authorizing-external-applications).

## Authorizing the API calls

Authorize your external application by creating an access token for it. Use the **App ID** and **App Secret** generated when you registered the application. The authorization method depends on the application's type, confidential or non-confidential.

Learn more about the [authorization methods](https://docs.uipath.com/automation-cloud/automation-cloud/latest/api-guide/accessing-uipath-resources-using-external-applications) for external apps.

Send the token as a bearer token on your requests. A token is valid for one hour. To keep calling the API after that, generate a new access token or [request a refresh token](https://docs.uipath.com/automation-cloud/automation-cloud/latest/api-guide/accessing-uipath-resources-using-external-applications#obtaining-a-refresh-token).

## Folder scope

An external application must target a single folder on every request, using the **X-UIPATH-FolderKey** header, and it needs the **Connections.View** permission in that folder. Requests that omit the header, and requests that ask for all folders, are rejected.

A connection that exists in a different folder from the one you targeted is reported as not found, rather than as forbidden.

## Available endpoints

The API guide currently documents these endpoints:

* [Get connections](https://docs.uipath.com/integration-service/automation-cloud/latest/api-guide/get-connections-endpoint)
* [Get connection by ID](https://docs.uipath.com/integration-service/automation-cloud/latest/api-guide/get-connection-endpoint)
* [Download custom connector](https://docs.uipath.com/integration-service/automation-cloud/latest/api-guide/download-custom-connector-endpoint)

Responses to an external application omit the connection owner, the element instance ID, the polling interval, and the bring-your-own-app flag. A connection's configuration is returned only to callers holding the configuration read scope, and secret values such as API keys and OAuth tokens are never returned.

For details on each endpoint, see the [Integration Service API guide](https://docs.uipath.com/integration-service/automation-cloud/latest/api-guide).
