How to obtain Autotask credentials

Appxite

Introduction

This article describes how to obtain the Autotask credentials required for the Platform – Autotask integration setup. The integration uses the Autotask REST API to synchronize Organizations, Products, Contracts, and Invoice Line data between Autotask and the Platform.

To learn more about the Autotask integration, see Autotask integration overview.

In this article

Before you start

Make sure the following are in place before you begin:

  • Autotask Admin access, or an Autotask admin who can create resources on your behalf.
  • Autotask's Integration/API add-on enabled on the tenant — API access isn't available on every Autotask license tier. If the API User option is missing from the Admin menu, ask Autotask/Datto support to enable it.

You don't need to know your Autotask Zone or base URL in advance. The Platform discovers it automatically from the Username you enter.

Required credentials

To connect Autotask with the Platform, you need to provide the following credentials:

Credential Description
Username The Autotask API user email address
Secret The password/API secret that you generate for the Autotask API user

Create a dedicated Security Level

You don't assign permissions directly to Autotask API users — instead, you assign a Security Level, and that Security Level's checkboxes are what actually gate every API call. Build a dedicated one for this integration rather than reusing an existing admin or user Security Level, so the integration's access stays auditable and scoped to what the Platform actually needs.

To create the Security Level, follow these steps:

  1. In Autotask, go to Admin → Account Settings & Users → Resources/Users (HR) → Security Levels. (The exact path/label varies slightly by Autotask version — look for "Security Levels" under the Admin/HR section.)
  2. Clone the built-in API User (system) Security Level.
  3. Name it clearly, for example AppXite API Integration.
  4. Click Save.

Create an API User in Autotask

To create the API user, follow these steps:

  1. Log in to Autotask as an admin.
  2. Go to Admin → Account Settings & Users → Resources/Users (HR) → Resources/Users → New. (In some Autotask versions: Admin → Integrations → API Users.)
  3. In the display name field, enter a name that makes the integration identifiable later, for example AppXite Integration.
  4. In the Security Level field, assign the Security Level you created in the previous section.
  5. In the credential fields, enter the Username and Password for the API user.
  6. In the Integration Vendor dropdown, select AppXite. Don't check the Custom (Internal Integration) checkbox. If "AppXite" doesn't appear in the list, contact Platform Support before proceeding — this usually means the tenant's Autotask instance hasn't yet synced the vendor catalog.
  7. Click Save. Copy the Username and Password immediately into a password manager — Autotask doesn't show the password again after this point.

Caution: Step 6 is not optional. The Platform is a registered Autotask integration vendor with a fixed vendor tracking code. The Platform's backend sends that code on every request; if the API user isn't associated with the AppXite vendor entry, Autotask rejects the calls with an authentication error even though the Username and Password are correct.

 

Note: The Integration Vendor identifier and the Custom (Internal Integration) identifier aren't two styles of the same setting — they are structurally different tracking IDs. Custom (Internal Integration) creates an identifier that is local to that one Autotask database only. An Integration Vendor identifier (such as AppXite's) is issued by Datto and works across any tenant's Autotask instance, which is required because the Platform connects to many different partners' Autotask databases. This is why you must select AppXite as the Integration Vendor rather than configuring it as Custom — the two aren't interchangeable, and Custom never works for a multi-tenant integration.

Enter credentials into the Platform

To connect the Platform to your Autotask instance, follow these steps:

  1. In the Platform, go to Settings → Integrations → PSA Tools → Autotask → Authentication tab.
  2. In the Username and Secret fields, enter the credentials from the previous section.
  3. Click Test Connection, and then click Save Authentication Settings. The Platform performs Zone discovery and a test call. A successful connection displays the discovered Autotask instance name and Zone as a read-only diagnostic value below the form.
  4. If the test fails, see Troubleshooting.

Required permissions

Grant the Security Level full Create/Read/Update/Delete access (as applicable) on the following Autotask entities, so the integration can synchronize data and post billing information:

  • Companies — to synchronize Organizations
  • Contracts — to read and map Recurring Service Contracts
  • Services — to map Products to their Autotask Service records
  • Contract Services and Contract Service Adjustments — to post recurring Invoice Lines
  • Contract Charges — to post non-recurring Invoice Lines
  • Billing Codes — to populate the Material Code dropdown in Settings → Configuration

Caution: If the Security Level is missing permission on any of these entities, synchronization may connect successfully but fail to load data, or fail specifically when posting Contract Service Adjustments or Contract Charges.

Troubleshooting

Symptom Likely cause Fix
Connection test fails immediately with an auth/zone error Username typo, or the account was deactivated Re-check the username exactly as shown in Autotask and confirm the API user is still active.
Auth error even though Username/Secret look correct The API user wasn't linked to the AppXite Integration Vendor, or Custom (Internal Integration) was checked instead In Autotask, edit the API user, select AppXite in the Integration Vendor dropdown, uncheck Custom (Internal Integration), and save. Then re-enter credentials in the Platform.
Connects, but Organizations or Contracts don't load The Security Level is missing permission on that entity Add the missing permission on the Security Level and re-test.
Sync fails when posting adjustments or charges The Security Level is missing permission on Contract Service Adjustments, Contract Charges, or Contract Services Grant full CRUD on all listed entities.
Password lost or never copied Autotask only shows it once Reset the password on the API user, then update the credential in the Platform immediately — the old password stops working the moment you set a new one.

Security notes

  • Treat the API user's password like any other secret — it grants write access to Contracts and billing on the tenant's behalf. The Platform stores it in Key Vault, not in plaintext configuration.
  • If you remove or disconnect the integration, deactivate the API user in Autotask (Admin → Resources) rather than leaving it enabled with no consumer. The dedicated Security Level can stay in place unused, or you can remove it once no resource references it.
  • Rotating the password requires re-entering the new value on the Platform's Authentication tab — there's no automatic sync of a rotated password.

Summary

This article explained how to obtain the Autotask credentials required for the Platform integration setup, including the Username and Secret, how to create a dedicated Security Level and API User with the correct Integration Vendor assignment, and how to enter and verify those credentials on the Platform's Authentication tab. It also covered the Autotask permissions required for synchronization and common troubleshooting scenarios.

Related content

Was this article helpful?

0 out of 0 found this helpful

Add comment

Please sign in to leave a comment.