Skip to main content

Understand data visibility and adviser context

API credentials represent an application operating in an agreed organisation or subscription context. They are not simply a substitute for an individual user's MyCRM login.

Owned records and shared records​

A record shared with a user or organisation in the MyCRM application may not be available through the API. Integrations should operate on the records covered by their own access agreement. This can explain differences between a screen in MyCRM and an API search or report.

Do not infer permissions from a known identifier. Relationships and included resources are also subject to the access rules applied by the API.

What UserId means​

Send the assigned adviser contact identifier in the UserId header. It can be supplied with credentials, shown on the API settings page, or obtained through permitted adviser-detail access.

For writes, the adviser context is used for attribution such as creator or last modifier; when creating a lead it affects allocation. A missing or invalid adviser context can produce 403. It must identify an adviser the application is allowed to act for.

On many reads, UserId does not alter the result. Some collection searches require it or use it to narrow the results. Follow the endpoint's requirements and the error message returned by the API.

Three separate questions​

  1. Who is the application? The OAuth client and bearer token.
  2. What may it do? The token's scopes.
  3. Which records and adviser context apply? The data access agreement and permitted user context.

Changing UserId does not bypass scopes or grant access to another organisation's records. For beta endpoints, a valid resolved user may also be necessary for the feature to be enabled.

For a step-by-step adviser lookup and write example, see Update information in MyCRM.