Toast
How to get your Toast API access credentials
In short
In Toast Web, open Integrations, then Toast API access, then Manage credentials. Use the arrow next to Create new credentials and choose Standard API. Name them, pick read-only scopes and your locations, and select Confirm. Then copy the API access URL, Client ID and Client secret into the app that needs them.
Before you start
- Each location needs Toast's Restaurant Management Suite Essentials plan or higher. Locations without it show grayed out, with a lock.
- You need the Manage Integrations permission at each location, and you have to be an active employee there.
- Standard API access only reads. It can't change anything in Toast.
Create the credentials
- Sign in to Toast Web. Open Integrations, then Toast API access, then Manage credentials.
- Select the down arrow next to Create new credentials, then Standard API.
- Give them a name you'll recognize, like the app they're for.
- Pick the scopes, the kinds of data they can read. For OK Book Sync, pick
orders:read,config:readandrestaurants:read. - Pick the locations: all of them, or the ones you want, then Apply.
- Select Confirm. Toast emails you a confirmation that lists each location's name and ID.
- Copy the Client secret as soon as Toast shows it, and keep it somewhere safe. Then copy the API access URL and Client ID from the credentials.
Lost the secret? Rotate it on the credentials page to get a new one, then paste the new one wherever the old one was used.
Where to find each location's ID
Each location has an ID that looks like 1f9c2a7e-0b4d-4c55-9a51-3c2e7f0d8b61. Toast also calls it a GUID. It's in Toast's confirmation email, and on the credentials in Toast Web. Apps use it to ask Toast for one location's data at a time.
Keep them safe
- Treat the client secret like a password. Don't email it or paste it into chats.
- If it gets out, rotate the secret on the same credentials page in Toast Web, then paste the new one into the app.
- A management group can have up to 100 sets of credentials, so give each app its own. Then you can turn one off without touching the others.
Using them with OK Book Sync
On the setup's Connect Toast step, paste the API access URL, Client ID and Client secret. The app checks them right away. Then, on Your stores, paste each location's ID, one per line. The secret is kept encrypted for your Windows user on the QuickBooks PC, and your sales go from Toast to that PC and into QuickBooks without passing through our servers.